Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,381
- High8,702
- Medium6,686
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-25569—28.5%
——9——CVE-2025-5479—28.5%
——9——CVE-2025-13243—28.5%
——9——CVE-2025-0817—28.5%
——9——CVE-2025-52468—28.5%
——9——CVE-2024-29798—28.5%
——9——CVE-2010-1487—28.5%
——9——CVE-2025-2830—28.5%
——9——CVE-2024-29795—28.5%
——9——CVE-2025-31964—28.5%
——9——CVE-2024-360328.1 HIG28.5%
——9In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: qca: fix info leak when fetching fw build id
Add the missing sanity checks and move the 255-byte build-id buffer off
the stack to avoid leaking stack data through debugfs in case the
build-info reply is malformed.43dCVE-2005-2351—28.5%
——9——CVE-2026-3419—28.5%
——9——CVE-2010-2913—28.5%
——9——CVE-2019-5632—28.5%
——9——CVE-2005-1330—28.4%
——9——CVE-2024-5591—28.5%
——9——CVE-2025-5477—28.4%
——9——CVE-2025-63694—28.5%
——9——CVE-2023-4802—28.5%
——9——CVE-2008-6801—28.5%
——9——CVE-2026-580296.5 MED28.5%
——9Vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Api/ApiChangeAuthenticationData.Php, includes/Api/ApiLinkAccount.Php, includes/Api/ApiRemoveAuthenticationData.Php, includes/Specials/SpecialLinkAccounts.Php, includes/Specials/SpecialUnlinkAccounts.Php.
This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.69dCVE-2021-33453—28.5%
——9——CVE-2026-580469.9 CRI28.4%
——9Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.13dCVE-2007-1068—28.5%
——9——CVE-2026-175395.9 MED28.5%
——9RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of service for bidirectional IEC 60870-5-104 communication.13dCVE-2019-25581—28.5%
——9——CVE-2024-12834—28.4%
——9——CVE-2026-9509—28.5%
——9An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST requests to the ‘/api/migration’ endpoint. This request triggers a failure that halts critical processes, leaving the system offline until the services or server are manually restarted. As a result, access control readers cease to function, and potential failures may occur in third-party integrations. Since the exploit requires no privileges or user interaction and is trivial to automate, the impact on availability is high, and the effect extends to interconnected systems.57dCVE-2026-75297.5 HIG28.5%
——9The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for unauthenticated attackers to read and modify the plugin's banner, stockbar, and core settings — including saving/updating banner records, toggling stockbar/feature flags, changing the active banner, and uploading background-image files via wp_handle_upload() — without any nonce or capability check.35dCVE-2026-31933—28.5%
——9——CVE-2007-5024—28.5%
——9——CVE-2016-4593—28.5%
——9——CVE-2002-0790—28.5%
——9——CVE-2021-4268—28.5%
——9——CVE-2022-32872—28.5%
——9——CVE-2019-19604.4 MED28.5%
——9Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.23dCVE-2025-55158—28.5%
——9——CVE-2025-47529—28.5%
——9——CVE-2024-29761—28.5%
——9——