Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,321
- High8,309
- Medium6,577
- Low710
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-364607.8 HIG30.2%
——9VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.72dCVE-2017-2717—30.2%
——9——CVE-2022-34362—30.2%
——9——CVE-2023-26586—30.2%
——9——CVE-2022-36472—30.2%
——9——CVE-2024-20333—30.2%
——9——CVE-2025-8321—30.2%
——9——CVE-2016-5487—30.2%
——9——CVE-2023-0554—30.2%
——9——CVE-2025-10819—30.2%
——9——CVE-2008-1356—30.2%
——9——CVE-2022-36478—30.2%
——9——CVE-2025-8230—30.2%
——9——CVE-2011-1549—30.2%
——9——CVE-2010-2930—30.2%
——9——CVE-2021-43757—30.2%
——9——CVE-2003-1021—30.2%
——9——CVE-2026-712689.9 CRI30.2%
——9OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content to with no validation that file_path stays within the ./core directory. A path-validation function, validate_file_path, exists elsewhere in the codebase (webserver/credentials.py) but is never invoked from compile_program, leaving the sink unprotected.23dCVE-2025-10692—30.2%
——9——CVE-2025-60106—30.2%
——9——CVE-2026-150934.3 MED30.2%
——9IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.56dCVE-2022-36489—30.2%
——9——CVE-2024-56917—30.2%
——9——CVE-2021-45672—30.2%
——9——CVE-2023-2498—30.2%
——9——CVE-2024-4983—30.2%
——9——CVE-2025-31837—30.2%
——9——CVE-2024-45558—30.2%
——9——CVE-2023-35906—30.1%
——9——CVE-2023-2118—30.2%
——9——CVE-2025-57785—30.2%
——9——CVE-2023-33302—30.1%
——9——CVE-2022-36474—30.2%
——9——CVE-2025-2220—30.1%
——9——CVE-2022-27573—30.1%
——9——CVE-2026-516289.1 CRI30.1%
——9Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-54443—30.1%
——9Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering feed item titles and Read More links as anchor href attributes, allowing an attacker-controlled feed to provide a javascript: URI that executes when clicked in the Dashy origin. This issue is fixed in version 3.2.0.65dCVE-2026-516369.1 CRI30.1%
——9Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-517269.1 CRI30.1%
——9Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2024-5459—30.1%
——9——