Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-0493—27.2%
——8——CVE-2001-0067—27.2%
——8——CVE-2026-347336.5 MED27.2%
——8WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteSystemdPrivate.php contains a PHP operator precedence bug in its CLI-only access guard. The script is intended to run exclusively from the command line, but the guard condition !php_sapi_name() === 'cli' never evaluates to true due to how PHP resolves operator precedence. The ! (logical NOT) operator binds more tightly than === (strict comparison), causing the expression to always evaluate to false, which means the die() statement never executes. As a result, the script is accessible via HTTP without authentication and will delete files from the server's temp directory while also disclosing the temp directory contents in its response. At time of publication, there are no publicly available patches.54dCVE-2024-10362—27.2%
——8——CVE-2023-25985—27.2%
——8——CVE-2023-31171—27.2%
——8——CVE-2025-55471—27.2%
——8——CVE-2023-26327—27.2%
——8——CVE-2016-11084—27.2%
——8——CVE-2014-3986—27.2%
——8——CVE-2024-52812—27.2%
——8——CVE-2025-15009—27.2%
——8——CVE-2026-0574—27.2%
——8——CVE-2026-828807.5 HIG27.2%
——8YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE declarations containing SYSTEM entities pointing to local files, causing the crawler to exfiltrate file contents into the searchable index.16dCVE-2024-13781—27.2%
——8——CVE-2021-1432—27.2%
——8——CVE-2021-28709—27.2%
——8——CVE-2024-34579—27.2%
——8——CVE-2024-45327—27.2%
——8——CVE-2025-1905—27.2%
——8——CVE-2018-10190—27.2%
——8——CVE-2025-2085—27.2%
——8——CVE-2025-64268—27.2%
——8——CVE-2024-4205—27.2%
——8——CVE-2024-4002—27.2%
——8——CVE-2019-6697—27.2%
——8——CVE-2010-1446—27.2%
——8——CVE-2014-3982—27.2%
——8——CVE-2019-10426—27.2%
——8——CVE-2025-31415—27.2%
——8——CVE-2012-4572—27.2%
——8——CVE-2009-5023—27.2%
——8——CVE-2026-39972—27.2%
——8——CVE-2006-0678—27.2%
——8——CVE-2024-55991—27.2%
——8——CVE-2026-160626.6 MED27.2%
——8The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actions such as arbitrary file deletion, sensitive data retrieval, or remote code execution. This is an incomplete fix of the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7's earlier object-injection advisories.21dCVE-2026-577316.5 MED27.2%
——8Contributor Broken Access Control in Flatsome <= 3.20.5 versions.76dCVE-2026-599377.5 HIG27.2%
——8pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. This issue is fixed in version 6.14.0.69dCVE-2026-648987.8 HIG27.2%
——8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.34dCVE-2026-510836.5 MED27.2%
——8Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.61d