Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-77998—27.2%
——8Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing Joomla user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.8dCVE-2023-38272—27.2%
——8——CVE-2024-49572—27.2%
——8——CVE-2024-52485—27.2%
——8——CVE-2024-49525—27.2%
——8——CVE-2023-32740—27.2%
——8——CVE-2025-47207—27.1%
——8——CVE-2024-2170—27.1%
——8——CVE-2024-13393—27.1%
——8——CVE-2025-1195—27.1%
——8——CVE-2024-33585—27.1%
——8——CVE-2025-700679.8 CRI27.1%
——8Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation73dCVE-2026-27768—27.1%
——8——CVE-2025-10480—27.1%
——8——CVE-2019-18222—27.1%
——8——CVE-2017-14428—27.1%
——8——CVE-2018-1000514—27.1%
——8——CVE-2018-12198—27.1%
——8——CVE-2024-54354—27.1%
——8——CVE-2026-791206.5 MED27.1%
——8Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)16dCVE-2023-46122—27.1%
——8——CVE-2025-32632—27.1%
——8——CVE-2024-47268—27.1%
——8——CVE-2022-23033—27.1%
——8——CVE-2025-573938.8 HIG27.1%
——8A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.73dCVE-2024-33593—27.1%
——8——CVE-2025-52865—27.1%
——8——CVE-2024-47772—27.1%
——8——CVE-2026-0540—27.1%
——8——CVE-2024-2139—27.1%
——8——CVE-2023-4523—27.1%
——8——CVE-2026-28450—27.1%
——8——CVE-2023-28640—27.1%
——8——CVE-2025-55895—27.1%
——8——CVE-2024-2457—27.1%
——8——CVE-2021-20178—27.1%
——8——CVE-2024-2120—27.1%
——8——CVE-2024-2946—27.1%
——8——CVE-2019-4174—27.1%
——8——CVE-2024-2111—27.1%
——8——