Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,286
- High8,401
- Medium6,423
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-54274—23.0%
——7——CVE-2025-39581—23.0%
——7——CVE-2024-52015—23.0%
——7——CVE-2026-40419—23.0%
——7——CVE-2025-41233—23.0%
——7——CVE-2024-51020—23.0%
——7——CVE-2026-56310—23.0%
——7——CVE-2026-11400—23.0%
——7——CVE-2025-47111—22.9%
——7——CVE-2004-1445—23.0%
——7——CVE-2026-40313—23.0%
——7——CVE-2026-54133.7 LOW23.0%
——7A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functionality of the file /omnidocs/GetWebApiConfiguration. The manipulation of the argument connectionDetails leads to information disclosure. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.48dCVE-2024-45235—23.0%
——7——CVE-2024-51004—23.0%
——7——CVE-2017-18830—23.0%
——7——CVE-2010-2072—23.0%
——7——CVE-2026-93667.3 HIG23.0%
——7A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.50dCVE-2017-18837—23.0%
——7——CVE-2025-39579—23.0%
——7——CVE-2026-38616.5 MED23.0%
——7LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.65dCVE-2024-09536.1 MED23.0%
——7When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129.22dCVE-2026-33584—23.0%
——7——CVE-2025-39575—23.0%
——7——CVE-2020-7137—23.0%
——7——CVE-2019-11173—23.0%
——7——CVE-2026-3763—23.0%
——7——CVE-2024-5265—23.0%
——7——CVE-2024-52013—23.0%
——7——CVE-2021-2167—23.0%
——7——CVE-2025-39576—23.0%
——7——CVE-2018-3682—23.0%
——7——CVE-2025-64225—23.0%
——7——CVE-2026-190194.8 MED23.0%
——7A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks.29dCVE-2026-67287—23.0%
——7Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.15dCVE-2026-9638—23.0%
——7——CVE-2022-21388—23.0%
——7——CVE-2025-39577—23.0%
——7——CVE-2021-41835—23.0%
——7——CVE-2026-49071—23.0%
——7——CVE-2021-1824—23.0%
——7——