Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-49746—25.3%
——8——CVE-2021-476208.1 HIG25.3%
——8In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: refactor malicious adv data check
Check for out-of-bound read was being performed at the end of while
num_reports loop, and would fill journal with false positives. Added
check to beginning of loop processing so that it doesn't get checked
after ptr has been advanced.42dCVE-2024-39335—25.3%
——8——CVE-2025-54854—25.3%
——8——CVE-2023-33057—25.3%
——8——CVE-2025-12477—25.3%
——8——CVE-2023-33101—25.3%
——8——CVE-2025-31796—25.3%
——8——CVE-2025-516298.8 HIG25.3%
——8A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter.72dCVE-2005-1338—25.3%
——8——CVE-2019-3763—25.3%
——8——CVE-2020-2569—25.3%
——8——CVE-2026-75531—25.3%
——8Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted from or associated with an analyzed file was inserted directly into the inline JavaScript onclick handler used by the Submit to Lookyloo action.
Although the value was subject to HTML escaping by the template engine, it was embedded inside a JavaScript string within an HTML attribute. An attacker-controlled URL containing specially crafted characters could therefore break out of the JavaScript string and inject arbitrary JavaScript code.
The malicious script would execute in the context of the Pandora web application when a victim interacts with the affected Submit to Lookyloo control. Successful exploitation could allow an attacker to access information available to the victim's browser or perform actions using the victim's authenticated Pandora session.
The patch removes the observable value from the inline JavaScript handler. The URL is instead stored in an HTML data-url attribute and retrieved through the DOM dataset API when needed. Additional uses of innerHTML were also replaced with textContent as defensive hardening.29dCVE-2025-43768—25.3%
——8——CVE-2024-53811—25.3%
——8——CVE-2025-26961—25.3%
——8——CVE-2023-33049—25.3%
——8——CVE-2007-1782—25.3%
——8——CVE-2026-40629—25.3%
——8——CVE-2024-54728—25.3%
——8——CVE-2025-31824—25.3%
——8——CVE-2003-1120—25.3%
——8——CVE-2024-11193—25.3%
——8——CVE-2025-61938—25.3%
——8——CVE-2024-1125—25.3%
——8——CVE-2026-42459—25.3%
——8——CVE-2026-54201—25.3%
——8Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks
when serving these log files. As a result, attackers can obtain
sensitive error information or internal application details, potentially
aiding in further attacks. This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.8dCVE-2026-537814.3 MED25.3%
——8Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attackers who control a podcast feed or media URL can stream an unbounded response to local storage via the temp-file download path, exhausting disk or system resources on the host running the CLI.63dCVE-2024-42340—25.3%
——8——CVE-2017-13286—25.3%
——8——CVE-2009-4271—25.3%
——8——CVE-2022-35080—25.3%
——8——CVE-2008-3644—25.3%
——8——CVE-2024-21169—25.3%
——8——CVE-2007-1781—25.3%
——8——CVE-2020-11834—25.3%
——8——CVE-2022-35081—25.3%
——8——CVE-2020-11835—25.3%
——8——CVE-2026-34297—25.3%
——8——CVE-2019-25580—25.3%
——8——