Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,217
- High8,129
- Medium6,162
- Low606
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2007-1056—22.9%
——7——CVE-2019-25533—22.9%
——7——CVE-2016-2894—22.9%
——7——CVE-2020-32536.7 MED22.9%
——7A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by enabling the support tunnel, setting a key, and deriving the tunnel password. A successful exploit could allow the attacker to run any system command with root access on an affected device.30dCVE-2022-25608—22.9%
——7——CVE-2021-20197—22.9%
——7——CVE-2026-41423—22.9%
——7——CVE-2008-0697—22.9%
——7——CVE-2024-20397—22.9%
——7——CVE-2026-541277.4 HIG22.9%
——7Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.50dCVE-2025-48980—22.9%
——7——CVE-2026-23488—22.9%
——7——CVE-2026-52704—22.9%
——7——CVE-2025-20369—22.9%
——7——CVE-2024-12244—22.9%
——7——CVE-2008-2359—22.9%
——7——CVE-2026-40377—22.9%
——7——CVE-2007-1089—22.9%
——7——CVE-2025-53284—22.9%
——7——CVE-2014-0404—22.9%
——7——CVE-2012-0109—22.9%
——7——CVE-2018-11292—22.9%
——7——CVE-2021-27257—22.9%
——7——CVE-2012-3736—22.9%
——7——CVE-2025-8813—22.9%
——7——CVE-2026-102077.5 HIG22.9%
——7The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes WordPress's magic quotes protection, followed by direct concatenation into a SQL query without proper escaping or prepared statements in the qa_user_profile_card() function. This makes it possible for unauthenticated attackers to append additional SQL queries into existing queries, which can be used to extract sensitive information from the database.44dCVE-2025-10234—22.9%
——7——CVE-2024-21838—22.9%
——7——CVE-2024-0690—22.9%
——7——CVE-2025-6366—22.9%
——7——CVE-2026-118977.5 HIG22.9%
——7IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.37dCVE-2025-64347—22.9%
——7——CVE-2026-27384—22.9%
——7——CVE-2024-7054—22.9%
——7——CVE-2026-732656.5 MED22.9%
——7RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals without historical-version permission to disclose known historical object content. This issue is fixed in version 1.0.0-beta.11.1dCVE-2023-27114—22.9%
——7——CVE-2026-34024—22.9%
——7——CVE-2016-8224—22.9%
——7——CVE-2015-0601—22.9%
——7——CVE-2026-27647—22.9%
——7——