Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,415
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-64386—25.8%
——8——CVE-2025-0052—25.8%
——8——CVE-2001-0287—25.8%
——8——CVE-2025-63528—25.8%
——8——CVE-2025-15096—25.8%
——8——CVE-2025-47545—25.8%
——8——CVE-2024-24865—25.8%
——8——CVE-2023-47793—25.8%
——8——CVE-2002-0042—25.8%
——8——CVE-2023-5875—25.8%
——8——CVE-2026-750147.3 HIG25.8%
——8A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.26dCVE-2023-47776—25.8%
——8——CVE-2023-51397—25.8%
——8——CVE-2026-50846.5 MED25.8%
——8WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely.
The session handler generates the session id from an MD5 hash seeded with a call to the built-in rand() function. The rand function is passed a maximum value based on the process id, the epoch time and the reference address of the object, but this information will have no effect on the overall quality of the seed of the message digest.
The rand function is seeded by 32-bits and is predictable. It is considered unsuitable for cryptographic purposes.
Predictable session ids could allow an attacker to gain access to systems.
Note that WebDyne::Session versions 1.042 and earlier appear to be in separate distributions from WebDyne.44dCVE-2020-10051—25.8%
——8——CVE-2019-25503—25.8%
——8——CVE-2025-3158—25.8%
——8——CVE-2026-25413—25.8%
——8——CVE-2025-63526—25.8%
——8——CVE-2026-198267.3 HIG25.8%
——8A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation.29dCVE-2021-46744—25.8%
——8——CVE-2023-47780—25.8%
——8——CVE-2026-634355.3 MED25.8%
——8Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match and an overly greedy charset capture to decode only the first RFC 2047 encoded-word and mishandle surrounding or subsequent text. A crafted malformed encoded-word in an address display name or local part could cross ? delimiters and make decoded From, To, or Reply-To header values differ from the raw values inspected by a human reviewer or downstream parser, enabling apparent sender or recipient spoofing, phishing, or authorization-check bypass. This issue is fixed in version 2.9.1.13dCVE-2026-54290—25.8%
——8——CVE-2023-47762—25.8%
——8——CVE-2025-10477—25.8%
——8——CVE-2023-44984—25.8%
——8——CVE-2023-44985—25.8%
——8——CVE-2025-15157—25.8%
——8——CVE-2024-49321—25.7%
——8——CVE-2007-5555—25.7%
——8——CVE-2023-44332—25.7%
——8——CVE-2024-41596—25.7%
——8——CVE-2026-2554—25.7%
——8——CVE-2014-0974—25.7%
——8——CVE-2005-1124—25.7%
——8——CVE-2021-336278.2 HIG25.7%
——8An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.44.11, and 5.5 before 05.52.11 affecting FwBlockServiceSmm. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.35dCVE-2003-1010—25.7%
——8——CVE-2009-4997—25.7%
——8——CVE-2025-43546—25.7%
——8——