Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,286
- High8,401
- Medium6,423
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-34188—23.0%
——7——CVE-2022-4766—23.0%
——7——CVE-2025-66443—23.0%
——7——CVE-2024-5250—23.0%
——7——CVE-2025-52878—23.0%
——7——CVE-2026-18716.5 MED23.0%
——7TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request.
Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts.50dCVE-2025-25566—23.0%
——7——CVE-2025-32096—23.0%
——7——CVE-2024-268987.8 HIG23.0%
——7In the Linux kernel, the following vulnerability has been resolved:
aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts
This patch is against CVE-2023-6270. The description of cve is:
A flaw was found in the ATA over Ethernet (AoE) driver in the Linux
kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on
`struct net_device`, and a use-after-free can be triggered by racing
between the free on the struct and the access through the `skbtxq`
global queue. This could lead to a denial of service condition or
potential code execution.
In aoecmd_cfg_pkts(), it always calls dev_put(ifp) when skb initial
code is finished. But the net_device ifp will still be used in
later tx()->dev_queue_xmit() in kthread. Which means that the
dev_put(ifp) should NOT be called in the success path of skb
initial code in aoecmd_cfg_pkts(). Otherwise tx() may run into
use-after-free because the net_device is freed.
This patch removed the dev_put(ifp) in the success path in
aoecmd_cfg_pkts(), and added dev_put() after skb xmit in tx().38dCVE-2026-226228.8 HIG23.0%
——7Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.42dCVE-2026-93227.5 HIG23.0%
——7IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.29dCVE-2026-44266.5 MED23.0%
——7A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition.10dCVE-2024-12703—23.0%
——7——CVE-2025-46364—23.0%
——7——CVE-2025-7016—23.0%
——7——CVE-2016-1360—23.0%
——7——CVE-2024-7235—23.0%
——7——CVE-2026-183474.3 MED23.0%
——7The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to read arbitrary user metadata and sensitive user record fields — including email address, assigned roles, registration date, and any user_meta values — belonging to any WordPress user including administrators, by supplying a target user ID with a user-type context to the frontend collection endpoint.22dCVE-2025-10735—23.0%
——7——CVE-2017-16933—23.0%
——7——CVE-2024-13095—23.0%
——7——CVE-2025-54669—23.0%
——7——CVE-2025-51414—23.0%
——7——CVE-2025-25208—23.0%
——7——CVE-2023-21505—23.0%
——7——CVE-2026-466375.4 MED23.0%
——7Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.56dCVE-2024-49395—23.0%
——7——CVE-2026-561525.3 MED23.0%
——7Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.7dCVE-2026-712918.8 HIG23.0%
——7Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue calls shouldBeRenderedAsTwig, which gates rendering only on the field definition's allow_twig flag and a regex checking for , , or ; when true, the raw field value is compiled and rendered via with no sandboxing.15dCVE-2025-1797—23.0%
——7——CVE-2025-7354—23.0%
——7——CVE-2025-31673—23.0%
——7——CVE-2026-21868—23.0%
——7——CVE-2024-6124—23.0%
——7——CVE-2025-54678—23.0%
——7——CVE-2023-28959—23.0%
——7——CVE-2026-45209—23.0%
——7——CVE-2024-38737—23.0%
——7——CVE-2026-759796.3 MED23.0%
——7A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sqlText results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.20dCVE-2024-37862—23.0%
——7——