Vulnerabilities exploitable today
373,224in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,252
- High8,221
- Medium6,136
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-4678—24.9%
——7——CVE-2019-8453—24.9%
——7——CVE-2020-1824—24.9%
——7——CVE-2025-53618—24.9%
——7——CVE-2024-30266—24.9%
——7——CVE-2026-600606.3 MED24.9%
——7Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.59dCVE-2024-2308—24.9%
——7——CVE-2020-18900—24.9%
——7——CVE-2025-58578—24.9%
——7——CVE-2017-1270—24.9%
——7——CVE-2024-6450—24.9%
——7——CVE-2023-0469—24.9%
——7——CVE-2024-13377—24.9%
——7——CVE-2025-3837—24.9%
——7——CVE-2025-36099—24.9%
——7——CVE-2026-187818.1 HIG24.9%
——7The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.24dCVE-2023-32551—24.9%
——7——CVE-2020-12459—24.9%
——7——CVE-2026-76565—24.9%
——7Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.725dCVE-2025-34504—24.9%
——7——CVE-2002-2023—24.9%
——7——CVE-2014-2273—24.9%
——7——CVE-2006-6510—24.9%
——7——CVE-2022-27535—24.9%
——7——CVE-2011-0541—24.9%
——7——CVE-2024-49706—24.9%
——7——CVE-2020-0188—24.9%
——7——CVE-2023-26328—24.9%
——7——CVE-2024-3309—24.9%
——7——CVE-2026-76564—24.9%
——7Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.725dCVE-2018-18091—24.9%
——7——CVE-2025-6516—24.9%
——7——CVE-2024-54109—24.9%
——7——CVE-2024-3732—24.9%
——7——CVE-2026-31998—24.9%
——7——CVE-2007-0751—24.9%
——7——CVE-2001-0624—24.9%
——7——CVE-2026-409543.7 LOW24.9%
——7CVE-2026-40954
is an integer underflow vulnerability in the traffic parsing function of Secure
Access clients prior to 14.55. Attackers with intimate knowledge of and total
control over the tunnel protocol can create a non-persistent DoS against their
client60dCVE-2024-24871—24.9%
——7——CVE-2023-50677—24.9%
——7——