Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-40261—29.2%
——9——CVE-2024-11673—29.2%
——9——CVE-2026-4917—29.2%
——9——CVE-2017-0747—29.2%
——9——CVE-2017-0746—29.2%
——9——CVE-2024-50928—29.2%
——9——CVE-2021-38868—29.2%
——9——CVE-2025-14932—29.2%
——9——CVE-2026-754797.5 HIG29.2%
——9JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.31dCVE-2023-23860—29.2%
——9——CVE-2020-12311—29.2%
——9——CVE-2017-0732—29.2%
——9——CVE-2026-23891—29.2%
——9——CVE-2026-656567.8 HIG29.2%
——9Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.34dCVE-2020-12310—29.2%
——9——CVE-2019-11139—29.2%
——9——CVE-2024-35725—29.2%
——9——CVE-2024-20364—29.2%
——9——CVE-2024-35726—29.2%
——9——CVE-2026-15311—29.2%
——9——CVE-2009-0150—29.2%
——9——CVE-2024-42164—29.2%
——9——CVE-2026-262007.8 HIG29.2%
——9HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.65dCVE-2021-36753—29.2%
——9——CVE-2022-25837—29.2%
——9——CVE-2026-117986.1 MED29.2%
——9The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.71dCVE-2025-58188—29.2%
——9——CVE-2026-9620—29.2%
——9——CVE-2026-623168.8 HIG29.2%
——9Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through tools/list, and invoke execute_command with a valid UFO_MCP_API_KEY to read files or execute allowed operating system commands as the victim's user. This issue is fixed in version 3.0.8.8dCVE-2026-41889—29.2%
——9——CVE-2026-2207—29.2%
——9——CVE-2023-39531—29.2%
——9——CVE-2024-13637—29.2%
——9——CVE-2025-53893—29.2%
——9——CVE-2024-0409—29.2%
——9——CVE-2024-13151—29.2%
——9——CVE-2018-2406—29.2%
——9——CVE-2025-55472—29.2%
——9——CVE-2023-47783—29.2%
——9——CVE-2026-622057.1 HIG29.2%
——9OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. The issue is fixed in 2026.6.6.58d