Vulnerabilities exploitable today
372,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,212
- High8,119
- Medium6,159
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-6594—24.3%
——7——CVE-2024-28675—24.3%
——7——CVE-2024-29108—24.3%
——7——CVE-2023-45998—24.3%
——7——CVE-2016-3178—24.3%
——7——CVE-2026-46509—24.3%
——7——CVE-2026-285256.8 MED24.3%
——7SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows unauthenticated attackers to cause a denial of service by sending a crafted HTTP POST request to /upload with a malformed multipart boundary and controlled TCP stream timing. Attackers can trigger an integer underflow in the mg_http_multipart_continue_wait_for_chunk() function when the buffer length falls within a specific range, causing an out-of-bounds heap read past the allocated receive buffer to a local IPC socket.60dCVE-2023-45072—24.3%
——7——CVE-2024-27689—24.3%
——7——CVE-2025-6226—24.3%
——7——CVE-2023-45056—24.3%
——7——CVE-2024-45302—24.3%
——7——CVE-2026-194046.5 MED24.3%
——7A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.29dCVE-2023-46088—24.3%
——7——CVE-2023-47526—24.3%
——7——CVE-2008-3894—24.3%
——7——CVE-2024-1661—24.3%
——7——CVE-2024-29106—24.3%
——7——CVE-2023-41859—24.3%
——7——CVE-2023-45604—24.3%
——7——CVE-2023-46138—24.3%
——7——CVE-2023-46210—24.3%
——7——CVE-2023-45057—24.3%
——7——CVE-2026-166057.2 HIG24.3%
——7The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.17dCVE-2026-154786.3 MED24.3%
——7A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employeeList can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.61dCVE-2025-0745—24.3%
——7——CVE-2026-26016—24.3%
——7——CVE-2026-627086.4 MED24.3%
——7Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.30dCVE-2025-6211—24.3%
——7——CVE-2024-24834—24.3%
——7——CVE-2026-33429—24.3%
——7——CVE-2025-27406—24.3%
——7——CVE-2026-284446.5 MED24.3%
——7Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId but fetches logs solely by resultId without verifying that the result belongs to the authorized typebot, leading to IDOR. An authenticated attacker can supply their own typebotId alongside any victim's resultId to read execution logs from other workspaces, leaking sensitive data including HTTP response bodies, AI model outputs, and webhook payloads. Every other result-scoped endpoint in the same router properly validates that the resultId belongs to the authorized typebotId. This confirms the missing check is an oversight, not a design choice. This issue has been fixed in version 3.15.2.51dCVE-2026-542676.1 MED24.3%
——7Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, to optimize client-side bootstrap in Server-Side Rendered (SSR) environments, Angular supports Hydration via provideClientHydration(). During SSR, Angular serializes the application's runtime state (such as cached HttpClient responses) and outputs it into the HTML stream as a <script> tag with a predictable identifier. During client bootstrap, Angular recovers this state by looking up the element via document.getElementById('ng-state') and parsing its text content. Because the DOM element lookup for the state container is predictable and relies solely on the ID selector (ng-state), it is susceptible to DOM Clobbering. If the application binds untrusted user input or CMS content to element properties such as id (e.g., <div [id]="userInput"> or <a id="ng-state">) before the genuine <script> tag is parsed by the browser, the attacker-controlled element takes precedence in the DOM lookup. During hydration, when Angular calls document.getElementById('ng-state'), the browser returns the attacker's clobbered element. Angular then attempts to parse the text content or attributes of this clobbered element as JSON. This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.65dCVE-2025-59886—24.3%
——7——CVE-2023-40681—24.3%
——7——CVE-2018-15749—24.3%
——7——CVE-2025-66307—24.3%
——7——CVE-2024-13390—24.3%
——7——CVE-2023-45010—24.3%
——7——