Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,224
- High7,931
- Medium6,433
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2008-4440—27.7%
——8——CVE-2020-25266—27.7%
——8——CVE-2024-10227—27.7%
——8——CVE-2025-4203—27.7%
——8——CVE-2017-15530—27.7%
——8——CVE-2026-750934.3 MED27.7%
——8A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX Initializer Loader. Such manipulation leads to incorrect calculation of buffer size. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 66b10bda8895f4bfaf8c205361f0125cdf51f99b. It is best practice to apply a patch to resolve this issue.27dCVE-2007-3200—27.7%
——8——CVE-2013-2069—27.7%
——8——CVE-2008-4406—27.7%
——8——CVE-2006-5806—27.7%
——8——CVE-2024-11945—27.7%
——8——CVE-2021-1064—27.7%
——8——CVE-2026-24974—27.7%
——8——CVE-2024-12621—27.7%
——8——CVE-2019-18192—27.7%
——8——CVE-2026-24981—27.7%
——8——CVE-2025-13687—27.7%
——8——CVE-2024-12453—27.7%
——8——CVE-2006-0227—27.7%
——8——CVE-2026-30846—27.7%
——8——CVE-2026-27045—27.7%
——8——CVE-2026-32519—27.7%
——8——CVE-2025-8814—27.7%
——8——CVE-2026-49083—27.7%
——8——CVE-2026-32488—27.7%
——8——CVE-2015-7433—27.7%
——8——CVE-2024-8209—27.7%
——8——CVE-2004-2440—27.7%
——8——CVE-2015-7434—27.7%
——8——CVE-2002-1782—27.7%
——8——CVE-2005-4659—27.7%
——8——CVE-2024-8071—27.7%
——8——CVE-2026-77536.5 MED27.7%
——8The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions up to, and including, 3.6.17. The handler only verifies a nonce, but the corresponding `ccb_export_nonce` is broadcast on every wp-admin page (including pages reachable to Subscribers, such as `/wp-admin/profile.php`) by the `ccb_add_admin_nonces` callback hooked to `admin_head`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export every calculator's full configuration — including stored Stripe secret keys, PayPal client secrets, Razorpay secret keys, webhook secret keys, and reCAPTCHA secret keys.35dCVE-2026-281718.6 HIG27.7%
——8Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.23dCVE-2025-46659—27.7%
——8——CVE-2017-4977—27.7%
——8——CVE-2026-45433—27.7%
——8This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle (MITM) attacks on the targeted device.56dCVE-2024-49528—27.7%
——8——CVE-2026-554755.7 MED27.7%
——8Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.64dCVE-2021-31797—27.7%
——8——