Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,753
- Medium6,799
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-29772—29.6%
——9——CVE-2026-750136.5 MED29.6%
——9A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in null pointer dereference. The attack can be launched remotely. The exploit is now public and may be used.29dCVE-2026-393597.5 HIG29.6%
——9Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remoted). The authd process allows agents to select a group during enrollment but does not filter path traversal sequences such as "..." While the manager checks for the group directory using wopendir(), the ".." sequence references the parent directory (/var/ossec/etc), allowing it to pass validation. After the malicious group is accepted and stored in the manager's global database, the remoted process uses this unchecked value to build paths for agent configuration synchronization. As a result, sensitive files from /var/ossec/etc, such as client.keys, ossec.conf, and internal certificates, are included in the agent's shared configuration stream and exposed to the attacker. This issue has been fixed in versions 4.10.4 and 4.14.5.60dCVE-2018-14791—29.6%
——9——CVE-2024-29789—29.6%
——9——CVE-2025-30073—29.6%
——9——CVE-2026-750126.5 MED29.6%
——9A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Password Configuration Handler. The manipulation leads to null pointer dereference. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.29dCVE-2026-1135—29.6%
——9——CVE-2026-338226.1 MED29.6%
——9Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.56dCVE-2017-17471—29.6%
——9——CVE-2021-3759—29.6%
——9——CVE-2025-25055—29.6%
——9——CVE-2024-2816—29.6%
——9——CVE-2026-817898.6 HIG29.6%
——9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal.
This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.7dCVE-2025-6524—29.6%
——9——CVE-2024-6082—29.6%
——9——CVE-2025-46575—29.6%
——9——CVE-2023-1521—29.6%
——9——CVE-2024-35345—29.6%
——9——CVE-2026-601786.6 MED29.6%
——9Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).52dCVE-2024-29764—29.6%
——9——CVE-2024-29775—29.6%
——9——CVE-2025-30351—29.6%
——9——CVE-2024-24937—29.6%
——9——CVE-2019-20781—29.6%
——9——CVE-2023-31082—29.6%
——9——CVE-2026-46607—29.6%
——9——CVE-2020-9361—29.6%
——9——CVE-2025-37177—29.6%
——9——CVE-2015-10125—29.6%
——9——CVE-2024-10366—29.6%
——9——CVE-2026-21693—29.6%
——9——CVE-2024-30184—29.6%
——9——CVE-2025-25724—29.6%
——9——CVE-2024-30183—29.6%
——9——CVE-2017-17470—29.6%
——9——CVE-2026-605856.6 MED29.6%
——9Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).52dCVE-2026-418507.5 HIG29.6%
——9Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.57dCVE-2026-44859—29.6%
——9——CVE-2023-48913—29.6%
——9——