Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-95274.3 MED26.7%
——8A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of the argument fname causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.55dCVE-2026-31971—26.7%
——8——CVE-2024-45985—26.7%
——8——CVE-2021-45660—26.7%
——8——CVE-2025-13618—26.7%
——8——CVE-2023-44266—26.7%
——8——CVE-2026-905608.2 HIG26.7%
——8zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.1dCVE-2025-53637—26.7%
——8——CVE-2023-20003—26.7%
——8——CVE-2025-29496—26.7%
——8——CVE-2026-555155.0 MED26.7%
——8Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset, allowing a reports user in one company to delete pending checkout acceptance records for another company. This issue is fixed in version 8.6.2.64dCVE-2026-95184.3 MED26.7%
——8A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the component Students Controller. The manipulation of the argument Name leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.55dCVE-2017-5703—26.7%
——8——CVE-2024-1434—26.7%
——8——CVE-2024-7618—26.7%
——8——CVE-2021-28705—26.7%
——8——CVE-2019-11276—26.7%
——8——CVE-2022-3879—26.7%
——8——CVE-2026-726428.8 HIG26.7%
——8The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required to upload and deploy a trained model can craft a model that reads and writes memory outside the intended allocation. The result is heap corruption that crashes the inference process, and, with sufficient control over the heap layout, could allow arbitrary code execution in the context of that process.15dCVE-2023-51370—26.7%
——8——CVE-2019-18388—26.7%
——8——CVE-2015-0663—26.7%
——8——CVE-2026-628977.0 HIG26.7%
——8Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.33dCVE-2021-4150—26.7%
——8——CVE-2019-3688—26.7%
——8——CVE-2023-51534—26.7%
——8——CVE-2026-23484—26.7%
——8——CVE-2026-2199—26.7%
——8——CVE-2026-2217—26.7%
——8——CVE-2002-0303—26.7%
——8——CVE-2024-7241—26.7%
——8——CVE-2025-29489—26.7%
——8——CVE-2023-26930—26.7%
——8——CVE-2026-54011—26.7%
——8——CVE-2023-51536—26.7%
——8——CVE-2026-736116.8 MED26.7%
——8File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the renewal endpoint.7dCVE-2024-39698—26.7%
——8——CVE-2025-29490—26.7%
——8——CVE-2023-51691—26.7%
——8——CVE-2025-29491—26.7%
——8——