Vulnerabilities exploitable today
372,967in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,239
- Medium6,225
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-256797.8 HIG24.1%
——7RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Echo Port tab that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a buffer overflow payload with a POP POP RET gadget chain and shellcode that triggers code execution when pasted into the Port field and the Change button is clicked.50dCVE-2023-7153—24.1%
——7——CVE-2026-02807.2 HIG24.1%
——7An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.
Cloud NGFW and Panorama are not impacted by this vulnerability.32dCVE-2025-23596—24.1%
——7——CVE-2023-43814—24.1%
——7——CVE-2025-23699—24.1%
——7——CVE-2013-5177—24.1%
——7——CVE-2025-54300—24.1%
——7——CVE-2023-27520—24.1%
——7——CVE-2026-6612—24.1%
——7——CVE-2020-37083—24.1%
——7——CVE-2026-59982—24.1%
——7——CVE-2024-45800—24.1%
——7——CVE-2024-6283—24.1%
——7——CVE-2026-37538—24.1%
——7——CVE-2026-40093—24.1%
——7——CVE-2024-13153—24.1%
——7——CVE-2024-13864—24.1%
——7——CVE-2026-44315—24.1%
——7——CVE-2024-27362—24.1%
——7——CVE-2026-505777.4 HIG24.1%
——7ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter unchanged in app/vau/VAUProtokoll.py while constructing VAU messages. The frozen client request counter causes the server side to reuse AES-GCM nonce and key combinations across responses. A network attacker who collects repeated ciphertexts can recover the XOR of plaintexts and use predictable inner HTTP headers and JSON fields to recover sensitive data, including patient health records. Repeated nonces can also enable recovery of the GHASH authentication key through the Joux forbidden attack, allowing forged AES-GCM messages and injection of malicious responses. The response-counter check also fails to maintain last_response_counter, weakening replay and ordering validation. This issue is fixed in version 1.3.0.4dCVE-2025-45317—24.1%
——7——CVE-2025-49089—24.1%
——7——CVE-2023-4920—24.1%
——7——CVE-2014-2906—24.1%
——7——CVE-2024-43326—24.1%
——7——CVE-2024-55635—24.1%
——7——CVE-2026-399086.5 MED24.1%
——7OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job starts, the application attempts to load proxies from the UNC path, triggering an SMB authentication attempt that discloses the NTLMv2 hash, which can then be relayed or cracked offline.51dCVE-2019-25330—24.1%
——7——CVE-2024-10055—24.1%
——7——CVE-2022-45176—24.1%
——7——CVE-2025-6101—24.1%
——7——CVE-2024-5152—24.1%
——7——CVE-2024-24716—24.1%
——7——CVE-2024-7598—24.1%
——7——CVE-2024-23170—24.1%
——7——CVE-2024-46394—24.1%
——7——CVE-2022-22652—24.1%
——7——CVE-2026-122095.3 MED24.1%
——7A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/index.js of the component Template Filter Handler. Such manipulation leads to improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.50dCVE-2013-3786—24.1%
——7——