Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,371
- High8,693
- Medium6,718
- Low721
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-11463—30.1%
——9——CVE-2023-4106—30.1%
——9——CVE-2025-47791—30.1%
——9——CVE-2026-541288.4 HIG30.1%
——9Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.58dCVE-2025-66786—30.1%
——9——CVE-2026-510256.1 MED30.1%
——9Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageController.java file59dCVE-2026-3734—30.1%
——9——CVE-2018-12221—30.1%
——9——CVE-2024-49252—30.1%
——9——CVE-2023-2608—30.1%
——9——CVE-2026-278857.2 HIG30.1%
——9Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extract sensitive data from the database, including user credentials, email addresses, and all stored content. This issue has been patched in version 16.3.0.56dCVE-2023-49914—30.1%
——9——CVE-2009-2461—30.1%
——9——CVE-2005-1379—30.1%
——9——CVE-2011-3977—30.1%
——9——CVE-2009-1388—30.1%
——9——CVE-2005-2962—30.1%
——9——CVE-2026-44321—30.1%
——9——CVE-2025-66379—30.1%
——9——CVE-2005-2519—30.1%
——9——CVE-2018-1677—30.1%
——9——CVE-2025-12819—30.1%
——9——CVE-2026-62992—30.1%
——9Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating that a requested path lies within a configured secure directory. An attacker able to place or reference a symlink within a directory Smarty treats as trusted (e.g., a template or config directory) could use it to point outside the intended secure directory, bypassing the containment check and reading arbitrary files accessible to the PHP process. This issue is fixed in versions 5.8.2 and 4.5.7.9dCVE-2026-42580—30.1%
——9——CVE-2026-497989.3 CRI30.1%
——9Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.58dCVE-2023-48060—30.1%
——9——CVE-2026-547133.7 LOW30.1%
——9CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can influence job parameters can submit semantically different data that produces the same identifier, resulting in legitimate jobs dropped as duplicate collisions. This issue is fixed in version 2.3.1.21dCVE-2026-24204—30.1%
——9——CVE-2026-783178.8 HIG30.1%
——9SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.17dCVE-2011-3123—30.1%
——9——CVE-2024-45960—30.1%
——9——CVE-2019-6744—30.1%
——9——CVE-2026-46618—30.1%
——9——CVE-2018-19963—30.1%
——9——CVE-2025-36070—30.1%
——9——CVE-2020-0574—30.1%
——9——CVE-2011-3124—30.1%
——9——CVE-2026-51259—30.1%
——9Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.49dCVE-2010-3576—30.1%
——9——CVE-2023-38653—30.1%
——9——