Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-0407—27.3%
——8——CVE-2023-41137—27.3%
——8——CVE-2026-3563—27.3%
——8——CVE-2025-52996—27.3%
——8——CVE-2007-3379—27.3%
——8——CVE-2026-476528.2 HIG27.3%
——8Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.55dCVE-2026-839915.5 MED27.3%
——8Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.8dCVE-2021-39027—27.3%
——8——CVE-2016-0237—27.3%
——8——CVE-2025-5690—27.3%
——8——CVE-2012-5179—27.3%
——8——CVE-2025-147326.4 MED27.3%
——8The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to, and including, 3.35.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.53dCVE-2022-42824—27.3%
——8——CVE-2023-32712—27.3%
——8——CVE-2025-8980—27.3%
——8——CVE-2026-812118.8 HIG27.3%
——8IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.10hCVE-2021-29073—27.3%
——8——CVE-2023-22109—27.3%
——8——CVE-2024-0130—27.3%
——8——CVE-2026-163547.5 HIG27.3%
——8Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.54dCVE-2024-12336—27.3%
——8——CVE-2014-3423—27.3%
——8——CVE-2011-1500—27.3%
——8——CVE-2014-0249—27.3%
——8——CVE-2007-5373—27.3%
——8——CVE-2026-687566.6 MED27.3%
——8A party with write access to stored session data may affect JFrog Artifactory under specific conditions.14dCVE-2006-3378—27.3%
——8——CVE-2026-826644.3 MED27.3%
——8A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknown part of the file app/Http/Controllers/Site/HomeController.php of the component JSON-LD Theme Handler. The manipulation of the argument Search leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.1.1 is able to mitigate this issue. The identifier of the patch is 67abfd864a15d169a78429f3290c91cb3b93e849. Upgrading the affected component is recommended.15dCVE-2026-87159.6 CRI27.3%
——8Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.18dCVE-2024-12069—27.3%
——8——CVE-2018-15807—27.3%
——8——CVE-2015-7020—27.3%
——8——CVE-2016-9378—27.3%
——8——CVE-2024-7047—27.3%
——8——CVE-2006-1814—27.3%
——8——CVE-2011-3869—27.3%
——8——CVE-2013-3236—27.3%
——8——CVE-2024-1400—27.3%
——8——CVE-2018-254338.2 HIG27.3%
——8Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery component to execute arbitrary SQL queries and retrieve sensitive data like usernames and password hashes.56dCVE-2011-1551—27.3%
——8——