Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,213
- High8,121
- Medium6,188
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2005-0620—24.5%
——7——CVE-2019-11166—24.5%
——7——CVE-2023-22421—24.5%
——7——CVE-2008-4984—24.5%
——7——CVE-2023-52284—24.5%
——7——CVE-2025-58841—24.5%
——7——CVE-2015-7238—24.5%
——7——CVE-2008-3930—24.5%
——7——CVE-2026-29192—24.5%
——7——CVE-2026-688457.8 HIG24.5%
——7Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.4dCVE-2021-1593—24.5%
——7——CVE-2026-46723—24.5%
——7——CVE-2026-653107.5 HIG24.5%
——7ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network access can read live process
values and server configuration.16dCVE-2014-8733—24.5%
——7——CVE-2023-1654—24.5%
——7——CVE-2026-78353.1 LOW24.5%
——7A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string processing.52dCVE-2026-33954—24.5%
——7——CVE-2022-3556—24.5%
——7——CVE-2013-7128—24.5%
——7——CVE-2025-53630—24.5%
——7——CVE-2023-1639—24.5%
——7——CVE-2026-440703.1 LOW24.5%
——7An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted character conversion requests.52dCVE-2023-45698—24.5%
——7——CVE-2009-2904—24.5%
——7——CVE-2023-1630—24.5%
——7——CVE-2024-6520—24.5%
——7——CVE-2025-59383—24.5%
——7——CVE-2019-10688—24.5%
——7——CVE-2005-0580—24.5%
——7——CVE-2026-689809.1 CRI24.5%
——7Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.39dCVE-2022-47180—24.5%
——7——CVE-2026-3172—24.5%
——7——CVE-2021-46775—24.5%
——7——CVE-2013-3272—24.5%
——7——CVE-2025-66030—24.5%
——7——CVE-2026-156734.4 MED24.5%
——7The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: the malicious payload is stored in the 'checkout_payment_plans' and 'order_status' settings via update_option() and executed later when the cod_to_prepaid_cart_notification_sendsms_hook WP-Cron event fires SA_CodTOPrepaid::sendSms().47dCVE-2026-537564.9 MED24.5%
——7Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter is directly interpolated into SQL queries without any filtering. The vulnerability is reachable through the auth cookie validation path, where $username is extracted from the cookie and passed unfiltered into SQL — guarded only by an HMAC signature that requires AUTH_KEY to forge. This issue has been patched in version 2.6.16.4dCVE-2014-8519—24.5%
——7——CVE-2024-45504—24.5%
——7——CVE-2017-18429—24.5%
——7——