Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-17050—26.1%
——8——CVE-2000-0363—26.1%
——8——CVE-2020-23552—26.1%
——8——CVE-2024-21261—26.1%
——8——CVE-1999-1318—26.1%
——8——CVE-2020-23553—26.1%
——8——CVE-2001-1091—26.1%
——8——CVE-2026-555456.5 MED26.1%
——8Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic without ObjectPrivilegeType.ReadPacket, ProcessingApi.subscribeAlgorithmStatus exposes the algorithm-status WebSocket topic without ObjectPrivilegeType.ReadAlgorithm, and MdbOverrideApi.subscribeMdbChanges exposes the mdb-changes WebSocket topic without SystemPrivilege.GetMissionDatabase. A low-privilege authenticated user can receive telemetry packets, algorithm status, and mission database change information outside the assigned authorization scope. This issue is fixed in versions 5.12.8 and 5.13.2.7dCVE-2025-52512—26.1%
——8——CVE-2009-1805—26.1%
——8——CVE-1999-1403—26.1%
——8——CVE-2025-47887—26.1%
——8——CVE-2017-202708.2 HIG26.1%
——8Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with option=com_twitchtv and view parameters containing SQL injection payloads to extract sensitive database information including credentials and configuration data.25dCVE-2019-25374—26.1%
——8——CVE-2017-10668—26.1%
——8——CVE-2026-554724.3 MED26.1%
——8Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This issue is fixed in version 8.6.2.64dCVE-2026-598028.2 HIG26.1%
——8PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain.63dCVE-2025-8401—26.1%
——8——CVE-2025-54334—26.1%
——8——CVE-2025-63713—26.1%
——8——CVE-2022-38470—26.1%
——8——CVE-2024-29909—26.1%
——8——CVE-2026-385779.8 CRI26.1%
——8Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.14dCVE-2025-68877—26.1%
——8——CVE-2025-68870—26.1%
——8——CVE-2024-41806—26.1%
——8——CVE-2025-57882—26.1%
——8——CVE-2017-16550—26.1%
——8——CVE-2021-21614—26.1%
——8——CVE-2024-29788—26.1%
——8——CVE-2025-63589—26.1%
——8——CVE-2024-51992—26.1%
——8——CVE-2023-32502—26.1%
——8——CVE-2026-40919—26.1%
——8——CVE-2025-30723—26.1%
——8——CVE-2023-38471—26.1%
——8——CVE-2024-4450—26.1%
——8——CVE-2024-2277—26.1%
——8——CVE-2024-29912—26.1%
——8——CVE-2024-35728—26.1%
——8——