Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-37765—26.1%
——8——CVE-2018-5957—26.1%
——8——CVE-2020-23555—26.1%
——8——CVE-2026-0887—26.1%
——8——CVE-2023-47523—26.1%
——8——CVE-2013-4216—26.1%
——8——CVE-2023-37766—26.1%
——8——CVE-2020-23560—26.1%
——8——CVE-2024-34376—26.1%
——8——CVE-2025-8401—26.1%
——8——CVE-2025-63713—26.1%
——8——CVE-2026-598028.2 HIG26.1%
——8PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain.63dCVE-2025-54334—26.1%
——8——CVE-2024-29765—26.1%
——8——CVE-2022-36466—26.1%
——8——CVE-2017-202688.2 HIG26.1%
——8Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL payloads to extract sensitive database information including database names and table structures.25dCVE-2017-17049—26.1%
——8——CVE-2018-5956—26.1%
——8——CVE-2000-0363—26.1%
——8——CVE-2017-17050—26.1%
——8——CVE-2017-202698.2 HIG26.1%
——8Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive information.25dCVE-2026-554724.3 MED26.1%
——8Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This issue is fixed in version 8.6.2.64dCVE-2009-1805—26.1%
——8——CVE-2017-10668—26.1%
——8——CVE-2018-5958—26.1%
——8——CVE-2019-25374—26.1%
——8——CVE-2017-202708.2 HIG26.1%
——8Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with option=com_twitchtv and view parameters containing SQL injection payloads to extract sensitive database information including credentials and configuration data.25dCVE-2025-47887—26.1%
——8——CVE-2001-1091—26.1%
——8——CVE-2026-555456.5 MED26.1%
——8Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic without ObjectPrivilegeType.ReadPacket, ProcessingApi.subscribeAlgorithmStatus exposes the algorithm-status WebSocket topic without ObjectPrivilegeType.ReadAlgorithm, and MdbOverrideApi.subscribeMdbChanges exposes the mdb-changes WebSocket topic without SystemPrivilege.GetMissionDatabase. A low-privilege authenticated user can receive telemetry packets, algorithm status, and mission database change information outside the assigned authorization scope. This issue is fixed in versions 5.12.8 and 5.13.2.7dCVE-2026-41201—26.0%
——8——CVE-2017-0736—26.0%
——8——CVE-2025-57538—26.0%
——8——CVE-2024-35656—26.0%
——8——CVE-2026-33381—26.0%
——8——CVE-2024-22162—26.0%
——8——CVE-2025-8218—26.0%
——8——CVE-2024-13449—26.0%
——8——CVE-2017-0773—26.0%
——8——CVE-2023-46622—26.0%
——8——