Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-13537—27.3%
——8——CVE-2021-34987—27.3%
——8——CVE-2021-44188—27.3%
——8——CVE-2022-42077—27.3%
——8——CVE-2025-36424—27.3%
——8——CVE-2009-1147—27.3%
——8——CVE-2025-61689—27.3%
——8——CVE-2022-42086—27.3%
——8——CVE-2024-37440—27.3%
——8——CVE-2025-53619—27.3%
——8——CVE-2024-33940—27.3%
——8——CVE-2022-42409—27.3%
——8——CVE-2010-4525—27.3%
——8——CVE-2023-28013—27.3%
——8——CVE-2008-2288—27.3%
——8——CVE-2011-1551—27.3%
——8——CVE-2021-43027—27.3%
——8——CVE-2000-0461—27.3%
——8——CVE-2018-254338.2 HIG27.3%
——8Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery component to execute arbitrary SQL queries and retrieve sensitive data like usernames and password hashes.56dCVE-2004-2398—27.3%
——8——CVE-2015-7019—27.3%
——8——CVE-2024-1400—27.3%
——8——CVE-2018-15807—27.3%
——8——CVE-2015-7020—27.3%
——8——CVE-2006-1814—27.3%
——8——CVE-2011-3869—27.3%
——8——CVE-2013-3236—27.3%
——8——CVE-2024-7047—27.3%
——8——CVE-2016-9378—27.3%
——8——CVE-2024-0407—27.3%
——8——CVE-2025-52996—27.3%
——8——CVE-2023-41137—27.3%
——8——CVE-2026-3563—27.3%
——8——CVE-2019-17100—27.2%
——8——CVE-2026-583734.3 MED27.2%
——8CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the parent_id query parameter of the quality reports API endpoint. Attackers can send requests with sequential integer parent_id values and distinguish between existing and non-existing reports via HTTP 500 versus HTTP 404 response differences, disclosing cross-organization report existence without returning report content.64dCVE-2026-457477.5 HIG27.2%
——8Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected Lua TLS scripting could crash Suricata, resulting in denial of service. Version 7.0.16 contains a fix. As a workaround, avoid Lua scripts that call TLS certificate information helpers on untrusted traffic (`TlsGetCertInfo` function), or update scripts to handle missing certificate fields where possible.6dCVE-2021-33630—27.2%
——8——CVE-2021-21792—27.2%
——8——CVE-2026-32275—27.2%
——8——CVE-2025-0214—27.2%
——8——