Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-3115—26.8%
——8——CVE-2025-47993—26.8%
——8——CVE-2026-626477.4 HIG26.8%
——8A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device.2dCVE-2026-55424.3 MED26.8%
——8A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /modstaffinfo.php of the component Parameter Handler. Executing a manipulation of the argument userid can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.53dCVE-2026-818456.3 MED26.8%
——8A vulnerability has been found in arben-adm mcp-sequential-thinking up to 0.5.0. Impacted is the function import_session/export_session of the file mcp_sequential_thinking/server.py of the component Import Session/Export Session. Such manipulation of the argument file_path leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.6.0 is recommended to address this issue. The name of the patch is 2fad3ee8ab1d0868b6c1afb5895bc336a10e5267. Upgrading the affected component is recommended.15dCVE-2024-29114—26.8%
——8——CVE-2024-31108—26.8%
——8——CVE-2026-94686.3 MED26.8%
——8A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The affected element is the function handleInitializeMemoryBank of the file src/index.ts. The manipulation of the argument projectPath results in path traversal. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.55dCVE-2026-28123—26.8%
——8——CVE-2024-30524—26.8%
——8——CVE-2023-54340—26.8%
——8——CVE-2024-10725—26.8%
——8——CVE-2023-22002—26.8%
——8——CVE-2025-587078.1 HIG26.8%
——8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion.
This issue affects Spin: from n/a through 1.8.55dCVE-2026-28118—26.8%
——8——CVE-2024-12445—26.8%
——8——CVE-2026-4992—26.8%
——8——CVE-2025-4669—26.8%
——8——CVE-2026-4845—26.8%
——8——CVE-2026-679777.5 HIG26.7%
——8An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.7dCVE-2023-45854—26.7%
——8——CVE-2015-7437—26.7%
——8——CVE-2024-31274—26.7%
——8——CVE-2025-0657—26.7%
——8——CVE-2016-3419—26.7%
——8——CVE-2011-5117—26.7%
——8——CVE-2017-18869—26.7%
——8——CVE-2025-66436—26.7%
——8——CVE-2006-1997—26.7%
——8——CVE-2004-0655—26.7%
——8——CVE-2024-29927—26.7%
——8——CVE-2024-29925—26.7%
——8——CVE-2024-30446—26.7%
——8——CVE-2020-8711—26.7%
——8——CVE-2025-48482—26.7%
——8——CVE-2025-53650—26.7%
——8——CVE-2012-6302—26.7%
——8——CVE-2003-0202—26.7%
——8——CVE-2012-4417—26.7%
——8——CVE-2025-12592—26.7%
——8——