Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-48964—26.2%
——8——CVE-2026-48874—26.2%
——8——CVE-2017-0345—26.2%
——8——CVE-2025-22392—26.2%
——8——CVE-2023-26351—26.2%
——8——CVE-2005-4796—26.2%
——8——CVE-2023-26342—26.2%
——8——CVE-2026-693736.7 MED26.2%
——8Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.7dCVE-2017-0308—26.2%
——8——CVE-2022-42176—26.2%
——8——CVE-2023-26343—26.2%
——8——CVE-2026-32291—26.2%
——8——CVE-2026-32524—26.2%
——8——CVE-2026-281568.5 HIG26.2%
——8Subscriber SQL Injection in Do Lasso <= 358 versions.32dCVE-2022-42412—26.2%
——8——CVE-2022-40201—26.2%
——8——CVE-2026-502367.4 HIG26.2%
——8An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.7dCVE-2023-26339—26.2%
——8——CVE-2025-45475—26.2%
——8——CVE-2017-0322—26.2%
——8——CVE-2023-1385—26.2%
——8——CVE-2026-144469.8 CRI26.2%
——8IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.41dCVE-2026-733244.3 MED26.2%
——8Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.1dCVE-2018-6250—26.2%
——8——CVE-2026-598475.9 MED26.2%
——8A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.11dCVE-2023-26341—26.2%
——8——CVE-2023-26346—26.2%
——8——CVE-2017-0315—26.2%
——8——CVE-2024-10894—26.2%
——8——CVE-2026-573416.5 MED26.2%
——8Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.76dCVE-2026-574066.5 MED26.2%
——8Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6.64dCVE-2026-48882—26.2%
——8——CVE-2023-26350—26.2%
——8——CVE-2026-666588.5 HIG26.2%
——8Subscriber SQL Injection in Reviewer <= 3.14.2 versions.32dCVE-2025-47208—26.2%
——8——CVE-2023-42771—26.2%
——8——CVE-2026-803529.8 CRI26.2%
——8Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.
A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator.
This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2.
Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.1dCVE-2026-574046.5 MED26.2%
——8Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.9.64dCVE-2018-6248—26.2%
——8——CVE-2026-57334—26.2%
——8——