Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,210
- High7,849
- Medium6,390
- Low708
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-11171—28.1%
——8——CVE-2009-4162—28.1%
——8——CVE-2025-61990—28.1%
——8——CVE-2023-23601—28.1%
——8——CVE-2026-43884—28.1%
——8——CVE-2026-347589.1 CRI28.1%
——8OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version 10.0.42.54dCVE-2026-1241—28.1%
——8——CVE-2026-705837.8 HIG28.1%
——8Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.7dCVE-2026-695417.8 HIG28.1%
——8Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.8dCVE-2022-45202—28.1%
——8——CVE-2024-52296—28.1%
——8——CVE-2025-54858—28.1%
——8——CVE-2026-498315.5 MED28.1%
——8DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base path, meaning that any path writable by the DSpace (often 'tomcat') user is allowed. This constitutes a Path Traversal Vulnerability in the curate script. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0.14dCVE-2026-23984—28.1%
——8——CVE-2026-260076.5 MED28.1%
——8cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.6dCVE-2026-4592—28.1%
——8——CVE-2025-29486—28.1%
——8——CVE-2026-550658.1 HIG28.1%
——8Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an attacker-controlled project identifier. ProjectView.CanDelete in pkg/models/project_view_permissions.go does not establish that the view belongs to the path project, and ProjectView.Delete in pkg/models/project_view.go continues after the scoped project_views delete affects no rows. Its subsequent deletes select task_buckets and task_positions only by project_view_id, allowing cross-tenant destruction of Kanban assignments and ordering while leaving the victim view and tasks intact. This issue is fixed in version 2.4.0.16dCVE-2025-47556—28.1%
——8——CVE-2026-23477—28.1%
——8——CVE-2020-10751—28.1%
——8——CVE-2026-35223—28.1%
——8——CVE-2025-4745—28.1%
——8——CVE-2023-28164—28.1%
——8——CVE-2026-83616—28.1%
——8xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createProcessingInstruction(target, data) in lib/dom.js accepts an unvalidated target, while the requireWellFormed: true serializer checks only for a colon and the reserved case-insensitive xml name on 0.9.x and performs no target check on 0.8.x. Because serialization emits <?target data?>, a target containing >, ?, whitespace, or another invalid XML-name character can break the processing-instruction boundary and inject XML structure. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.8dCVE-2020-8341—28.1%
——8——CVE-2020-4640—28.1%
——8——CVE-2026-83607—28.1%
——8xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, Document.createElement(tagName) stores an unvalidated element name and XMLSerializer.serializeToString() emits that name verbatim. The requireWellFormed: true path did not validate the element qualified name or synthesized xmlns:PREFIX declaration, so attacker-controlled tag names could inject attributes, elements, or processing instructions into serialized XML or HTML and could cause cross-site scripting when browser-consumed. The unchecked values violate the XML QName constraint, and default serialization and creation-time createElement() behavior remain permissive. This issue is fixed in @xmldom/xmldom versions 0.8.14 and 0.9.11; no fixed version is available for xmldom.8dCVE-2024-10318—28.1%
——8——CVE-2022-28779—28.1%
——8——CVE-2019-10424—28.1%
——8——CVE-2024-46964—28.1%
——8——CVE-2011-3216—28.1%
——8——CVE-2022-40128—28.1%
——8——CVE-2024-46966—28.1%
——8——CVE-2025-57431—28.1%
——8——CVE-2019-5595—28.1%
——8——CVE-2021-31840—28.1%
——8——CVE-2026-22045—28.1%
——8——CVE-2025-9572—28.1%
——8——