Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,372
- High8,700
- Medium6,720
- Low721
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-18407—30.1%
——9——CVE-2024-45761—30.1%
——9——CVE-2026-828204.3 MED30.1%
——9A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as f412a33b9a84c2d1a9dee145a868feddbf64879e. A patch should be applied to remediate this issue. The project maintainer doubts the security impact: "While I acknowledged the bugs and provided fixes, I have yet to see any way to exploit these alleged vulnerabilities."17dCVE-2011-3214—30.1%
——9——CVE-2011-1828—30.1%
——9——CVE-2023-28020—30.1%
——9——CVE-2026-2693—30.1%
——9——CVE-2026-783148.8 HIG30.1%
——9SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.17dCVE-2026-658867.5 HIG30.1%
——9Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.44dCVE-2026-783168.8 HIG30.1%
——9SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.17dCVE-2014-9903—30.1%
——9——CVE-2024-34768—30.0%
——9——CVE-2025-8033—30.0%
——9——CVE-2025-10186—30.0%
——9——CVE-2026-416957.5 HIG30.0%
——9Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution.
Affected versions:
Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14.57dCVE-2026-22734—30.0%
——9——CVE-2023-30538—30.0%
——9——CVE-2015-6333—30.0%
——9——CVE-2026-500839.1 CRI30.0%
——9The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, CVE-50084, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices.71dCVE-2003-0794—30.0%
——9——CVE-2012-4453—30.0%
——9——CVE-2024-29934—30.0%
——9——CVE-2025-12335—30.0%
——9——CVE-2017-14577—30.0%
——9——CVE-2024-11129—30.0%
——9——CVE-2003-0334—30.0%
——9——CVE-2026-2468—30.0%
——9——CVE-2023-31416—30.0%
——9——CVE-2026-454748.4 HIG30.0%
——9Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.57dCVE-2026-454638.4 HIG30.0%
——9Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.57dCVE-2017-10743—30.0%
——9——CVE-2026-131077.1 HIG30.0%
——9IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.2dCVE-2024-5553—30.0%
——9——CVE-2026-727099.8 CRI30.0%
——9SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can bypass template-level authorization guards through direct HTTP requests to invoke actions such as editer_auteur, enabling arbitrary account password rewrites including administrator accounts and resulting in full account takeover.4dCVE-2023-50017—30.0%
——9——CVE-2025-12334—30.0%
——9——CVE-2026-580819.8 CRI30.0%
——9Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters.
An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.18dCVE-2025-23086—30.0%
——9——CVE-2017-14293—30.0%
——9——CVE-2019-15959—30.0%
——9——