Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,224
- High7,930
- Medium6,432
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-40409—27.7%
——8——CVE-2026-39962—27.7%
——8——CVE-2024-45077—27.7%
——8——CVE-2025-63648—27.7%
——8——CVE-2025-3889—27.7%
——8——CVE-2024-51142—27.7%
——8——CVE-2025-25025—27.7%
——8——CVE-2025-69328—27.7%
——8——CVE-2024-11827—27.7%
——8——CVE-2026-88013.5 LOW27.7%
——8Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules).
This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.69dCVE-2026-25400—27.7%
——8——CVE-2026-41645—27.7%
——8——CVE-2023-33719—27.7%
——8——CVE-2025-9099—27.7%
——8——CVE-2024-11928—27.7%
——8——CVE-2026-22345—27.7%
——8——CVE-2026-907756.5 MED27.7%
——8PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.3dCVE-2023-4500—27.7%
——8——CVE-2023-6072—27.7%
——8——CVE-2025-47553—27.7%
——8——CVE-2015-7432—27.7%
——8——CVE-2026-578188.1 HIG27.7%
——8A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.41dCVE-2026-494918.2 HIG27.7%
——8Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.56dCVE-2025-13824—27.7%
——8A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code 0xF019. To recover, clear the fault.13dCVE-2026-22346—27.7%
——8——CVE-2023-41343—27.7%
——8——CVE-2024-11226—27.7%
——8——CVE-2015-3171—27.7%
——8——CVE-2024-2088—27.7%
——8——CVE-2023-30778—27.7%
——8——CVE-2024-12496—27.7%
——8——CVE-2026-24976—27.7%
——8——CVE-2026-196117.4 HIG27.7%
——8A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.13dCVE-2024-369218.8 HIG27.7%
——8In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: guard against invalid STA ID on removal
Guard against invalid station IDs in iwl_mvm_mld_rm_sta_id as that would
result in out-of-bounds array accesses. This prevents issues should the
driver get into a bad state during error handling.43dCVE-2026-97577.5 HIG27.7%
——8The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters are read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing WordPress's wp_magic_quotes protection, which only covers $_POST/$_GET/$_COOKIE/$_REQUEST), then each is split on ',' via explode() and the resulting fragments are interpolated directly into a SQL BETWEEN clause in gmw_get_locations_within_boundaries_sql() without is_numeric() validation, (float) casting, esc_sql(), or $wpdb->prepare(). This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the site to host the Posts Locator search-results shortcode (`[gmw form="results" form_id=N]`) on a public page and to have at least one published post with an associated gmw_location row.57dCVE-2024-11870—27.7%
——8——CVE-2026-25359—27.7%
——8——CVE-2025-0163—27.7%
——8——CVE-2022-39404—27.7%
——8——CVE-2026-25358—27.7%
——8——