Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-54327—27.1%
——8——CVE-2014-5607—27.1%
——8——CVE-2024-29817—27.1%
——8——CVE-2023-44173—27.1%
——8——CVE-2024-29914—27.1%
——8——CVE-2001-0139—27.1%
——8——CVE-2022-44318—27.1%
——8——CVE-2025-20288—27.1%
——8——CVE-2026-188165.0 MED27.1%
——8A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authentication. The attack may be launched remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. Upgrading to version 2.3.3 addresses this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.34dCVE-2024-12579—27.1%
——8——CVE-2025-8781—27.1%
——8——CVE-2026-51297—27.1%
——8Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.47dCVE-2024-12598—27.1%
——8——CVE-2026-96057.3 HIG27.1%
——8A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d300. Applying a patch is the recommended action to fix this issue.54dCVE-2026-45010—27.1%
——8——CVE-2023-21593—27.1%
——8——CVE-2024-29814—27.1%
——8——CVE-2014-7995—27.1%
——8——CVE-2024-10545—27.1%
——8——CVE-2005-0964—27.1%
——8——CVE-2025-11038—27.1%
——8——CVE-2024-9157—27.1%
——8——CVE-2009-3432—27.1%
——8——CVE-2006-0202—27.1%
——8——CVE-2021-43997—27.1%
——8——CVE-2013-0159—27.1%
——8——CVE-2024-12331—27.1%
——8——CVE-2024-12462—27.1%
——8——CVE-2026-413635.3 MED27.1%
——8OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses file-system sandbox restrictions. Attackers can exploit improper path resolution during upload_image operations to read arbitrary files outside configured localRoots boundaries.53dCVE-2001-0143—27.1%
——8——CVE-2006-4435—27.1%
——8——CVE-2025-64353—27.1%
——8——CVE-2026-507709.8 CRI27.1%
——8An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.16dCVE-2024-29933—27.1%
——8——CVE-2020-14369—27.1%
——8——CVE-2024-32539—27.1%
——8——CVE-2026-32635—27.1%
——8——CVE-2026-81906—27.1%
——8Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that was fully authenticated for the callback response, with the login recorded and login events dispatched. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.5dCVE-2024-29803—27.1%
——8——CVE-2026-874718.1 HIG27.1%
——8Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)5d