Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-42509—29.3%
——9——CVE-2026-304589.1 CRI29.3%
——9An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.74dCVE-2024-32604—29.3%
——9——CVE-2026-1662—29.3%
——9——CVE-2024-31357—29.3%
——9——CVE-2026-172125.3 MED29.3%
——9IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.29dCVE-2023-1051—29.3%
——9——CVE-2023-33591—29.3%
——9——CVE-2002-1554—29.3%
——9——CVE-2017-13721—29.3%
——9——CVE-2024-35160—29.3%
——9——CVE-2025-15020—29.3%
——9——CVE-2024-29793—29.3%
——9——CVE-2009-5080—29.3%
——9——CVE-2020-36209—29.3%
——9——CVE-2007-1271—29.3%
——9——CVE-2002-1109—29.3%
——9——CVE-2026-367857.5 HIG29.3%
——9Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.57dCVE-2024-30613—29.3%
——9——CVE-2026-53502—29.3%
——9Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0.9dCVE-2025-22227—29.3%
——9——CVE-2018-14983—29.3%
——9——CVE-2012-1313—29.3%
——9——CVE-2024-4634—29.3%
——9——CVE-2024-42375—29.3%
——9——CVE-2012-3311—29.3%
——9——CVE-2008-3927—29.3%
——9——CVE-2016-2557—29.3%
——9——CVE-2005-1405—29.3%
——9——CVE-2000-0758—29.3%
——9——CVE-2004-2729—29.3%
——9——CVE-2026-888808.6 HIG29.3%
——9Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.8dCVE-2023-34869—29.3%
——9——CVE-2026-166605.3 MED29.3%
——9IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.7dCVE-2026-541788.1 HIG29.3%
——9backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDisk in src/app/Models/Traits/HasUploadFields.php trusts disk-relative paths from clear_<attribute>[] and passes them to Storage::disk()->delete without confirming that the paths are persisted on the current model record. An authenticated user with Update access to a CRUD using this mutator through src/app/Models/Traits/CrudTrait.php can delete another record's attachment, a shared asset, or another operational file on the configured disk by submitting its path. The newer MultipleFiles uploader is not affected because it intersects requested deletions with the record's persisted file list. This flaw does not permit reading the deleted files. The 5.x line remains affected through its final releases. This issue is fixed in versions 6.8.12 and 7.0.35.1dCVE-2026-608207.4 HIG29.3%
——9Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).29dCVE-2008-3883—29.3%
——9——CVE-2023-54341—29.3%
——9——CVE-2026-785506.6 MED29.3%
——9The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console.7dCVE-2006-0432—29.3%
——9——