Vulnerabilities exploitable today
373,224in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,252
- High8,221
- Medium6,136
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-1603—24.8%
——7——CVE-2026-56393—24.8%
——7——CVE-2024-27990—24.8%
——7——CVE-2026-40813—24.8%
——7——CVE-2026-674258.6 HIG24.8%
——7Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version 2.26.6.46dCVE-2024-29908—24.8%
——7——CVE-2024-32556—24.8%
——7——CVE-2024-26482—24.8%
——7——CVE-2025-31923—24.8%
——7——CVE-2024-32530—24.8%
——7——CVE-2025-3422—24.8%
——7——CVE-2025-66719—24.8%
——7——CVE-2024-32579—24.8%
——7——CVE-2024-27991—24.8%
——7——CVE-2026-23521—24.8%
——7——CVE-2023-5606—24.8%
——7——CVE-2024-21158—24.8%
——7——CVE-2024-56016—24.8%
——7——CVE-2025-0398—24.8%
——7——CVE-2025-27000—24.8%
——7——CVE-2026-274095.3 MED24.8%
——7Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Webba Booking: from n/a through 6.4.13.75dCVE-2025-24776—24.8%
——7——CVE-2026-40814—24.8%
——7——CVE-2011-2146—24.8%
——7——CVE-2026-7401—24.8%
——7——CVE-2026-56376—24.8%
——7——CVE-2026-54078—24.8%
——7veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/tools/DictionaryKeysHelper.java in getRichTextStringOrStreamEntryStringRepresentation(), where a crafted PDF containing a malicious rich-text /RC or /RV entry can cause external entity expansion and reflect local file contents into the validation report. This issue is fixed in versions 1.30.2 and 1.31.71.46dCVE-2026-203084.3 MED24.8%
——7A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.
This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.39dCVE-2025-11060—24.8%
——7——CVE-2023-48090—24.8%
——7——CVE-2016-3024—24.8%
——7——CVE-2026-352176.5 MED24.8%
——7NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker may still accept the malformed packet and install the subscription into internal broker state. Under a specific packet-length construction, the same parser flaw also causes a 1-byte out-of-bounds read that crosses the real heap allocation boundary and is detected by ASAN as a `heap-buffer-overflow`.
If the consumed byte happens to look acceptable, NanoMQ may continue and append the malformed subscription entry into its internal `subinfol` state. In that case, a `SUBSCRIBE` packet that should be rejected by MQTT rules is instead treated as a successful subscription. Whether ASAN reports the bug does not depend on MQTT's logical `remain` boundary; it depends on whether the read crosses the real heap allocation boundary of the underlying message buffer. In other words, these are not two unrelated issues. They are two manifestations of the same parsing defect: by default, it appears as a semantic vulnerability, and under suitable input conditions, it also becomes a verifiable out-of-bounds read vulnerability.53dCVE-2024-49677—24.8%
——7——CVE-2024-32571—24.8%
——7——CVE-2025-47472—24.8%
——7——CVE-2024-51646—24.8%
——7——CVE-2024-35209—24.8%
——7——CVE-2024-29004—24.8%
——7——CVE-2022-42829—24.8%
——7——CVE-2025-47480—24.8%
——7——