Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,708
- Medium6,690
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-32696—28.4%
——9——CVE-2025-2902—28.4%
——9——CVE-2016-2142—28.4%
——9——CVE-2018-20944—28.4%
——9——CVE-2018-6523—28.4%
——9——CVE-2016-9016—28.4%
——9——CVE-2025-11405—28.4%
——9——CVE-2019-11086—28.4%
——9——CVE-2026-854487.5 HIG28.4%
——9MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publisher can supply unbounded distinct community names to grow retained state and per-pass work without limit, causing memory exhaustion and performance degradation.2dCVE-2025-11402—28.4%
——9——CVE-2018-20939—28.4%
——9——CVE-2014-1272—28.4%
——9——CVE-2023-41241—28.4%
——9——CVE-2017-1681—28.4%
——9——CVE-2018-6524—28.4%
——9——CVE-2025-11400—28.4%
——9——CVE-2025-11401—28.4%
——9——CVE-2024-4695—28.4%
——9——CVE-2026-854457.5 HIG28.4%
——9MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without validation. Attackers can declare arbitrarily large packet counts to trigger unbounded memory allocation, exhausting system resources and causing service unavailability.8dCVE-2025-11487—28.4%
——9——CVE-2023-50124—28.4%
——9——CVE-2019-0129—28.4%
——9——CVE-2024-47254—28.4%
——9——CVE-2017-12711—28.4%
——9——CVE-2023-271264.6 MED28.4%
——9The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused across all cameras. An attacker with physical access to a camera is able to extract and decrypt sensitive data containing the Wifi password and the TP-LINK account credential of the victim.70dCVE-2024-6410—28.4%
——9——CVE-2024-48936—28.3%
——9——CVE-2009-0682—28.3%
——9——CVE-2020-23741—28.3%
——9——CVE-2024-12329—28.3%
——9——CVE-2013-4425—28.3%
——9——CVE-2024-4739—28.3%
——9——CVE-2025-58730—28.3%
——9——CVE-2020-37143—28.3%
——9——CVE-2011-1474—28.3%
——9——CVE-2026-5361—28.3%
——9——CVE-2012-0808—28.3%
——9——CVE-2013-1928—28.3%
——9——CVE-2026-414538.8 HIG28.3%
——9Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data.7dCVE-2025-6516—28.3%
——9——