Vulnerabilities exploitable today
373,224in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,252
- High8,221
- Medium6,136
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-27383—24.9%
——7——CVE-2024-3490—24.9%
——7——CVE-2024-13121—24.9%
——7——CVE-2019-10140—24.9%
——7——CVE-2022-4604—24.9%
——7——CVE-2023-50333—24.9%
——7——CVE-2024-37885—24.9%
——7——CVE-2025-6011—24.9%
——7——CVE-2024-3560—24.9%
——7——CVE-2023-39249—24.9%
——7——CVE-2026-19226—24.9%
——7——CVE-2024-1582—24.9%
——7——CVE-2026-9704—24.9%
——7——CVE-2025-67566—24.9%
——7——CVE-2024-41589—24.9%
——7——CVE-2026-793247.5 HIG24.9%
——7Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so no authentication, ownership or form key check is enforced.4dCVE-2016-10374—24.9%
——7——CVE-2024-37960—24.9%
——7——CVE-2025-2887—24.9%
——7——CVE-2024-10706—24.9%
——7——CVE-2026-24189—24.9%
——7——CVE-2024-1842—24.9%
——7——CVE-2024-1426—24.9%
——7——CVE-2024-1327—24.9%
——7——CVE-2026-37347—24.9%
——7——CVE-2011-0458—24.9%
——7——CVE-2023-6892—24.9%
——7——CVE-2022-29199—24.9%
——7——CVE-2026-202386.5 MED24.9%
——7In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search filters with the `OR` SPL operator, the injected filter overrides more restrictive filters on child roles.53dCVE-2026-105855.4 MED24.9%
——7A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The AnsweredQuestionStructuredDataComponent did not escape user-controlled Discussion titles before embedding them in a <script type="application/ld+json"> block, allowing the title to break out of the script context. The injection was escalated to a full cross-site scripting attack on GitHub Enterprise Server by leveraging JSONP callback support in the REST API to bypass the Content Security Policy. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.74dCVE-2019-25435—24.9%
——7——CVE-2024-41732—24.9%
——7——CVE-2026-195096.5 MED24.9%
——7Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ssid_number` parameter.11dCVE-2024-30197—24.9%
——7——CVE-2024-1521—24.9%
——7——CVE-2022-29193—24.9%
——7——CVE-2024-31257—24.9%
——7——CVE-2026-3220—24.9%
——7——CVE-2024-1364—24.9%
——7——CVE-2022-29200—24.9%
——7——