Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,381
- High8,702
- Medium6,686
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-0779—28.4%
——9——CVE-2025-12243—28.4%
——9——CVE-2025-0138—28.4%
——9——CVE-2025-24936—28.4%
——9——CVE-2025-14589—28.4%
——9——CVE-2023-48271—28.4%
——9——CVE-2026-503124.7 MED28.4%
——9Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.56dCVE-2026-370719.8 CRI28.4%
——9Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application configuration file and triggering a rebuild of configuration and resetting super administrator credentials to default values.14dCVE-2026-822547.5 HIG28.4%
——9gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out-of-memory process kills.19dCVE-2026-6908310.0 CRI28.4%
——9SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.21dCVE-2023-44102—28.4%
——9——CVE-2019-5626—28.4%
——9——CVE-2026-187499.8 CRI28.4%
——9The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case.8dCVE-2026-47382—28.4%
——9——CVE-2025-23008—28.4%
——9——CVE-2026-53640—28.4%
——9FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. While sibling write endpoints correctly enforce fine-grained permissions, the corresponding read endpoints have no authorization guards. Version 0.8.0 contains a fix. Some workarounds are available. Restrict staff accounts to only those who need access to sensitive data and/or use a reverse proxy or WAF to restrict access to the affected endpoints.71dCVE-2026-485697.1 HIG28.4%
——9Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.56dCVE-2022-44514—28.4%
——9——CVE-2026-491674.7 MED28.4%
——9Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.56dCVE-2026-83615—28.4%
——9xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js uses _copy to clone the complete currentNSMap for each nested element that declares a new namespace prefix. Keeping every ancestor map live on the parse stack creates quadratic peak namespace-map storage, so a small highly compressible XML document can exhaust the process heap before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.8dCVE-2025-22523—28.4%
——9——CVE-2024-32430—28.4%
——9——CVE-2026-49871—28.4%
——9——CVE-2025-9018—28.4%
——9——CVE-2025-13483—28.4%
——9——CVE-2016-7600—28.4%
——9——CVE-2025-0350—28.4%
——9——CVE-2024-32145—28.4%
——9——CVE-2026-12863—28.4%
——9——CVE-2026-31247—28.4%
——9——CVE-2023-3627—28.4%
——9——CVE-2025-30132—28.4%
——9——CVE-2023-1270—28.4%
——9——CVE-2025-14193—28.4%
——9——CVE-2026-50282—28.4%
——9Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete permission. Function craft\\controllers\\AssetsController::actionMoveFolder() supports moving an asset folder into a destination parent folder. If a folder with the same name already exists at the destination, the action can be called with force=true to overwrite the destination. This issue has been resolved in versions 5.9.21 and 4.17.14.76dCVE-2025-13256—28.4%
——9——CVE-2025-13263—28.4%
——9——CVE-2022-42447—28.4%
——9——CVE-2026-53643—28.4%
——9FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API endpoints. The root cause is a combination of the `can_always_access` module flag (which grants all staff access to certain modules) and insufficient permission checks or unsafe parameter handling on individual endpoints. Version 0.8.0 contains a fix. Some workarounds are available. Restrict staff accounts to only those who need access to sensitive settings and/or use a reverse proxy or WAF to restrict access to the affected endpoints to trusted IP addresses or higher-privilege roles.71dCVE-2025-14203—28.4%
——9——