Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-33228—29.0%
——9——CVE-2026-630996.5 MED29.0%
——9TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. Attackers can exploit the missing organization-scoped authorization check in AttachmentSrv.visible, which is implemented as a pass-through traversal, to download arbitrary attachments.62dCVE-2026-42984.3 MED29.0%
——9The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.70dCVE-2026-643828.8 HIG29.0%
——9In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_open() replay
A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_open_init() fails before the next send, cleanup
retains the previous buffer type and frees that response again.
Reset response bookkeeping before each attempt to prevent the stale free.13dCVE-2026-40009—28.9%
——9——CVE-2024-52456—29.0%
——9——CVE-2022-33287—29.0%
——9——CVE-2026-1779—29.0%
——9——CVE-2014-0018—29.0%
——9——CVE-2014-2277—29.0%
——9——CVE-1999-1174—29.0%
——9——CVE-2014-5881—29.0%
——9——CVE-2013-6436—29.0%
——9——CVE-2026-813537.8 HIG29.0%
——9Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.5hCVE-2023-51540—29.0%
——9——CVE-2024-38680—29.0%
——9——CVE-2005-4133—29.0%
——9——CVE-2024-31112—29.0%
——9——CVE-2024-37961—29.0%
——9——CVE-2024-52455—29.0%
——9——CVE-2024-38673—29.0%
——9——CVE-2026-43239—29.0%
——9——CVE-2019-19727—28.9%
——9——CVE-2024-29907—28.9%
——9——CVE-2019-13528—28.9%
——9——CVE-2024-6767—28.9%
——9——CVE-2024-36303—28.9%
——9——CVE-2020-36838—28.9%
——9——CVE-2024-45808—28.9%
——9——CVE-2016-8944—28.9%
——9——CVE-2018-13446—28.9%
——9——CVE-2024-4374—28.9%
——9——CVE-2026-35065—28.9%
——9——CVE-2026-2618—28.9%
——9——CVE-2020-36834—28.9%
——9——CVE-2025-24976—28.9%
——9——CVE-2015-0926—28.9%
——9——CVE-2007-5159—28.9%
——9——CVE-2010-3435—28.9%
——9——CVE-2016-0618—28.9%
——9——