Vulnerabilities exploitable today
372,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,214
- High8,131
- Medium6,162
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-46952—24.3%
——7——CVE-2012-5564—24.3%
——7——CVE-2023-44986—24.3%
——7——CVE-2025-68515—24.3%
——7——CVE-2010-4458—24.3%
——7——CVE-2024-3277—24.3%
——7——CVE-2025-0952—24.3%
——7——CVE-2022-43040—24.3%
——7——CVE-2023-35041—24.3%
——7——CVE-2024-2578—24.3%
——7——CVE-2023-4207—24.3%
——7——CVE-2022-29211—24.3%
——7——CVE-2021-45339—24.3%
——7——CVE-2025-8032—24.3%
——7——CVE-2025-67478—24.3%
——7——CVE-2025-11168—24.3%
——7——CVE-2024-30214—24.3%
——7——CVE-2008-5746—24.3%
——7——CVE-2026-88518.1 HIG24.3%
——7SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inject malicious SQL code to write extracted data into the sogo_acl table and retrieve it through the /acls API, establishing an out-of-band data exfiltration channel.51dCVE-2026-554375.4 MED24.3%
——7Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via `dangerouslySetInnerHTML` so HTML embedded in workspace agent log lines was rendered as live markup. Server-side sanitization did not neutralize HTML metacharacters. Exploitation requires a victim to view attacker-controlled agent logs in the dashboard. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 enables `escapeXML: true` so HTML metacharacters are escaped before DOM insertion. No known workarounds are available.66dCVE-2026-161847.0 HIG24.3%
——7IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.40dCVE-2024-32745—24.3%
——7——CVE-2024-6504—24.3%
——7——CVE-2026-175417.5 HIG24.3%
——7The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.17dCVE-2025-61775—24.3%
——7——CVE-2024-51518—24.3%
——7——CVE-2023-7306—24.3%
——7——CVE-2026-4564—24.3%
——7——CVE-2023-50830—24.3%
——7——CVE-2026-110889.6 CRI24.3%
——7Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)51dCVE-2022-22528—24.3%
——7——CVE-2022-41686—24.3%
——7——CVE-2022-47658—24.3%
——7——CVE-2022-1524—24.3%
——7——CVE-2018-4283—24.3%
——7——CVE-2024-13801—24.3%
——7——CVE-2026-25325—24.3%
——7——CVE-2025-22561—24.3%
——7——CVE-2024-13101—24.3%
——7——CVE-2026-4949—24.3%
——7——