Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,951
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-7582—26.9%
——8——CVE-2021-33438—26.9%
——8——CVE-2025-6909—26.9%
——8——CVE-2023-33922—26.9%
——8——CVE-2023-41804—26.9%
——8——CVE-2010-0729—26.9%
——8——CVE-2020-15372—26.9%
——8——CVE-2025-14657—26.9%
——8——CVE-2026-193897.1 HIG26.9%
——8Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.23hCVE-2025-48280—26.9%
——8——CVE-2023-52342—26.9%
——8——CVE-2025-65566—26.9%
——8——CVE-2025-7484—26.9%
——8——CVE-2026-34893—26.9%
——8——CVE-2025-7561—26.9%
——8——CVE-2025-48752—26.9%
——8——CVE-2026-40978—26.9%
——8——CVE-2024-8455—26.9%
——8——CVE-2025-7161—26.9%
——8——CVE-2024-7161—26.9%
——8——CVE-2025-7562—26.9%
——8——CVE-2026-61666—26.9%
——8websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.5dCVE-2026-736128.1 HIG26.9%
——8File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based isolation for confidentiality and integrity.7dCVE-2025-6850—26.9%
——8——CVE-2024-48178—26.9%
——8——CVE-2021-33448—26.9%
——8——CVE-2025-7559—26.9%
——8——CVE-2026-506808.2 HIG26.9%
——8Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.56dCVE-2026-770719.8 CRI26.9%
——8n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value without escaping. An attacker could inject a condition that widened the filter to match every row, turning an intended single-row operation into full-table disclosure, deletion, or modification.14dCVE-2026-33237—26.9%
——8——CVE-2026-751038.8 HIG26.9%
——8Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.29dCVE-2026-7987—26.9%
——8——CVE-2025-7589—26.9%
——8——CVE-2025-7212—26.9%
——8——CVE-2025-7556—26.9%
——8——CVE-2025-7560—26.9%
——8——CVE-2025-26619—26.9%
——8——CVE-2026-39558—26.9%
——8——CVE-2023-50775—26.9%
——8——CVE-2026-7018—26.9%
——8——