Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,216
- High7,868
- Medium6,398
- Low708
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-573787.5 HIG27.9%
——8Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7.65dCVE-2022-4867—27.9%
——8——CVE-2026-1370—27.9%
——8——CVE-2026-577057.5 HIG27.9%
——8Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.65dCVE-2025-4059—27.9%
——8——CVE-2016-5517—27.9%
——8——CVE-2025-50174—27.9%
——8——CVE-2005-0937—27.9%
——8——CVE-2025-12468—27.9%
——8——CVE-2007-6418—27.9%
——8——CVE-2026-22165—27.9%
——8——CVE-2025-65947—27.9%
——8——CVE-2025-70121—27.9%
——8——CVE-2021-3987—27.9%
——8——CVE-2024-50543—27.9%
——8——CVE-2018-12433—27.9%
——8——CVE-2018-21078—27.9%
——8——CVE-2024-36441—27.9%
——8——CVE-2025-22230—27.9%
——8——CVE-2002-1791—27.9%
——8——CVE-2022-26966—27.9%
——8——CVE-2020-16281—27.9%
——8——CVE-2020-13829—27.9%
——8——CVE-2025-44194—27.9%
——8——CVE-2024-21038—27.9%
——8——CVE-2016-11046—27.9%
——8——CVE-2022-36876—27.9%
——8——CVE-2016-4781—27.9%
——8——CVE-2025-22283—27.9%
——8——CVE-2025-11085—27.9%
——8——CVE-2026-42317—27.9%
——8GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the webserver has write rights on them. Upgrade to 10.0.25 or 11.0.7 to receive a patch.56dCVE-2010-0546—27.9%
——8——CVE-2025-60062—27.9%
——8——CVE-2019-0184—27.9%
——8——CVE-2026-825247.2 HIG27.9%
——8UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. Attackers can upload a PHP web shell to the public storage disk and execute arbitrary operating system commands on the server by accessing the uploaded file at the URL returned in the server response.13dCVE-2025-21123—27.9%
——8——CVE-2025-70123—27.9%
——8——CVE-2023-6630—27.9%
——8——CVE-2025-68494—27.9%
——8——CVE-2014-5421—27.9%
——8——