Vulnerabilities exploitable today
372,253in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,277
- High8,394
- Medium6,440
- Low634
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-12514—23.2%
——7——CVE-2026-34564—23.2%
——7——CVE-2026-751686.3 MED23.2%
——7An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to write arbitrary content to files within /uxx/config/ and /ugw/config/.3dCVE-2021-1235—23.2%
——7——CVE-2026-703708.8 HIG23.2%
——7Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT DISTINCTROW, GROUP BY, ORDER BY) with no whitelist validation.16dCVE-2026-31708—23.2%
——7——CVE-2026-479177.8 HIG23.2%
——7Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.14dCVE-2018-4036—23.2%
——7——CVE-1999-1044—23.2%
——7——CVE-1999-1187—23.2%
——7——CVE-2024-38518—23.2%
——7——CVE-2026-542766.1 MED23.2%
——7AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute. Further, the attacker is only receiving the digest, so should only be able to extract the user's credentials if the cryptography is weak or there is some kind of password reuse. This vulnerability is fixed in 3.14.1.73dCVE-2023-6522—23.2%
——7——CVE-2026-703698.8 HIG23.2%
——7Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, items.homebranch, items.ccode, biblioitems.itemtype, aqbudgets.budget_code, aqorders.sort1, and aqorders.sort2.16dCVE-2016-9869—23.2%
——7——CVE-2025-49340—23.2%
——7——CVE-2024-13520—23.2%
——7——CVE-2020-25746—23.2%
——7——CVE-2023-49098—23.2%
——7——CVE-2025-0578—23.2%
——7——CVE-2025-2702—23.2%
——7——CVE-2024-409717.3 HIG23.2%
——7In the Linux kernel, the following vulnerability has been resolved:
f2fs: remove clear SB_INLINECRYPT flag in default_options
In f2fs_remount, SB_INLINECRYPT flag will be clear and re-set.
If create new file or open file during this gap, these files
will not use inlinecrypt. Worse case, it may lead to data
corruption if wrappedkey_v0 is enable.
Thread A: Thread B:
-f2fs_remount -f2fs_file_open or f2fs_new_inode
-default_options
<- clear SB_INLINECRYPT flag
-fscrypt_select_encryption_impl
-parse_options
<- set SB_INLINECRYPT again38dCVE-2016-9868—23.2%
——7——CVE-2024-29109—23.2%
——7——CVE-2026-413696.5 MED23.2%
——7OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical system configurations and compromise host execution integrity.49dCVE-2017-20180—23.2%
——7——CVE-2025-20686—23.2%
——7——CVE-2017-10613—23.2%
——7——CVE-2017-9959—23.2%
——7——CVE-2024-29865—23.2%
——7——CVE-2023-3322—23.2%
——7——CVE-2026-1950—23.2%
——7——CVE-2026-3187—23.2%
——7——CVE-2026-703718.8 HIG23.2%
——7Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are not validated against any whitelist and land verbatim in identifier positions (SELECT DISTINCTROW, GROUP BY, ORDER BY), and each Filter slot is concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments with no bound parameters.16dCVE-2023-40399—23.2%
——7——CVE-2011-3440—23.2%
——7——CVE-2021-24822—23.2%
——7——CVE-2026-54595.3 MED23.1%
——7The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This makes it possible for unauthenticated attackers to activate a free subscription pack for any user on the site, overwriting their existing paid subscription and causing loss of paid features.65dCVE-2024-47918—23.1%
——7——CVE-1999-1486—23.1%
——7——