Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,224
- High7,938
- Medium6,434
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2013-5169—27.5%
——8——CVE-2026-273308.6 HIG27.5%
——8Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.19dCVE-2023-51330—27.5%
——8——CVE-2022-3233—27.5%
——8——CVE-2024-50512—27.5%
——8——CVE-2026-882778.8 HIG27.5%
——8GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.6dCVE-2023-52341—27.5%
——8——CVE-2025-64522—27.5%
——8——CVE-2025-6842—27.5%
——8——CVE-2025-1299—27.5%
——8——CVE-2024-2345—27.5%
——8——CVE-2025-51489—27.5%
——8——CVE-2013-0162—27.5%
——8——CVE-2009-1173—27.5%
——8——CVE-2026-866443.5 LOW27.5%
——8A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is able to resolve this issue. This patch is called a8ea1520850b4242f395247f72e87e597506cef0. Upgrading the affected component is recommended. The vendor confirms: "The fix [...] sets Mermaid `securityLevel` to `strict`, disables `htmlLabels`, and sanitizes rendered SVG with DOMPurify."8dCVE-2021-0053—27.5%
——8——CVE-2024-44682—27.5%
——8——CVE-2022-38231—27.5%
——8——CVE-2024-8675—27.5%
——8——CVE-2026-48500—27.5%
——8——CVE-2025-22249—27.5%
——8——CVE-2023-51318—27.5%
——8——CVE-2024-12713—27.5%
——8——CVE-2025-26696.0 MED27.5%
——8IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.78dCVE-2023-51312—27.5%
——8——CVE-2023-3506—27.5%
——8——CVE-2024-1419—27.5%
——8——CVE-2024-2803—27.5%
——8——CVE-2026-387522.9 LOW27.5%
——8A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.58dCVE-2025-28973—27.5%
——8——CVE-2024-39679—27.5%
——8——CVE-2024-9531—27.5%
——8——CVE-2025-59478—27.5%
——8——CVE-2024-3285—27.5%
——8——CVE-2024-2392—27.5%
——8——CVE-2025-47640—27.5%
——8——CVE-2023-36555—27.5%
——8——CVE-2020-368907.2 HIG27.5%
——8An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.37dCVE-2024-43237—27.5%
——8——CVE-2020-15774—27.5%
——8——