Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,213
- High8,121
- Medium6,188
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-9241—24.6%
——7——CVE-2019-25451—24.6%
——7——CVE-2006-1166—24.6%
——7——CVE-2019-4298—24.6%
——7——CVE-2014-4225—24.6%
——7——CVE-2023-47081—24.6%
——7——CVE-2020-4382—24.6%
——7——CVE-2025-54761—24.6%
——7——CVE-2026-44257—24.6%
——7——CVE-2018-3661—24.6%
——7——CVE-2025-2544—24.6%
——7——CVE-2024-47097—24.6%
——7——CVE-2014-7251—24.6%
——7——CVE-2025-12285—24.6%
——7——CVE-2025-2836—24.6%
——7——CVE-2026-735606.5 MED24.6%
——7vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through _fetch_image, requests.get, and Image.open instead of MediaConnector, bypassing allowed_media_domains and allowed_local_media_path protections and allowing server-side requests and reads of arbitrary files accessible to the vLLM process. This issue is fixed in version 0.26.0.26dCVE-2026-891755.3 MED24.6%
——7Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.2dCVE-2026-95267.3 HIG24.6%
——7A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the argument num_id results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.52dCVE-2026-21689—24.6%
——7——CVE-2026-841199.6 CRI24.6%
——7Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.11dCVE-2026-94477.3 HIG24.6%
——7A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search.php. Performing a manipulation of the argument Name results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.52dCVE-2026-478317.5 HIG24.6%
——7Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22.
Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.66dCVE-2026-673429.8 CRI24.6%
——7ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary database parameters.12dCVE-2023-3684—24.6%
——7——CVE-2026-32170—24.6%
——7——CVE-2024-57771—24.6%
——7——CVE-2024-5447—24.6%
——7——CVE-2025-14192—24.6%
——7——CVE-2011-3574—24.6%
——7——CVE-2024-2963—24.6%
——7——CVE-2021-25123—24.6%
——7——CVE-2004-1066—24.6%
——7——CVE-2026-27041—24.6%
——7——CVE-2023-28345—24.6%
——7——CVE-2015-6034—24.6%
——7——CVE-2018-16722—24.6%
——7——CVE-2026-781347.1 HIG24.6%
——7strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.2dCVE-2024-8708—24.6%
——7——CVE-2026-190706.3 MED24.6%
——7A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewadmin.php. The manipulation of the argument delid results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.31dCVE-2026-880248.3 HIG24.6%
——7Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.2d