Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,381
- High8,755
- Medium6,799
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-44859—29.6%
——9——CVE-2024-6579—29.6%
——9——CVE-2024-42655—29.6%
——9——CVE-2026-8719—29.6%
——9——CVE-2020-9540—29.6%
——9——CVE-2024-42165—29.6%
——9——CVE-2026-24891—29.6%
——9——CVE-2023-40679—29.6%
——9——CVE-2025-45583—29.6%
——9——CVE-2026-586407.3 HIG29.6%
——9Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.58dCVE-2018-252417.5 HIG29.6%
——9VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characters into the search bar to trigger an unhandled exception that terminates the application.59dCVE-2024-30440—29.6%
——9——CVE-2026-56385—29.6%
——9——CVE-2023-41938—29.6%
——9——CVE-2026-3302—29.6%
——9——CVE-2017-13686—29.6%
——9——CVE-2024-37276—29.6%
——9——CVE-2018-17487—29.6%
——9——CVE-2020-12362—29.6%
——9——CVE-2023-48129—29.6%
——9——CVE-2025-13221—29.6%
——9——CVE-2023-48128—29.6%
——9——CVE-2024-34449—29.6%
——9——CVE-2025-64169—29.6%
——9——CVE-2024-8180—29.6%
——9——CVE-2024-30434—29.6%
——9——CVE-2026-416817.5 HIG29.6%
——9rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the stack. This is reachable from safe Rust. This vulnerability is fixed in 0.10.78.65dCVE-2026-499716.1 MED29.6%
——9Laravel-Mediable before 7.0.0 contains a stored cross-site scripting vulnerability that allows authenticated or anonymous users to execute arbitrary JavaScript by uploading unsanitized SVG files containing embedded scripts in onload event handlers, script tags, or foreignObject elements. Attackers can store persistent XSS payloads in uploaded SVG files that execute with full DOM access when victims open or preview the file, enabling session cookie theft, CSRF token capture, and account takeover.66dCVE-2026-39815—29.6%
——9——CVE-2025-53133—29.6%
——9——CVE-2008-3901—29.6%
——9——CVE-2022-43476—29.6%
——9——CVE-2026-497907.3 HIG29.6%
——9Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability60dCVE-2024-42759—29.6%
——9——CVE-2023-37745—29.6%
——9——CVE-2025-53721—29.6%
——9——CVE-2026-703175.5 MED29.6%
——9Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.35dCVE-2023-48133—29.6%
——9——CVE-2026-924567.1 HIG29.6%
——9yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared Redis keys controlling customer auto-recycling behavior, causing mass customer data deletion, disabling lead recycling, or blocking customer creation across the deployment.2dCVE-2024-3178—29.6%
——9——