Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,231
- High8,285
- Medium6,315
- Low606
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-47076—22.7%
——7——CVE-2021-418388.2 HIG22.7%
——7An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of a Numeric Range Comparison Without a Minimum Check.30dCVE-2026-666617.7 HIG22.7%
——7Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.27dCVE-2025-30899—22.7%
——7——CVE-2022-31219—22.7%
——7——CVE-2023-6692—22.7%
——7——CVE-2023-3654—22.7%
——7——CVE-2022-49063—22.7%
——7——CVE-2010-5151—22.7%
——7——CVE-2010-5166—22.7%
——7——CVE-2010-5167—22.7%
——7——CVE-2026-34888—22.7%
——7——CVE-2025-12455—22.7%
——7——CVE-2010-5165—22.7%
——7——CVE-2026-791828.8 HIG22.7%
——7Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)14dCVE-2026-175427.5 HIG22.7%
——7The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.15dCVE-2026-759537.5 HIG22.7%
——7Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.15dCVE-2026-27913—22.7%
——7——CVE-2026-17289.8 CRI22.7%
——7Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.
Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.31dCVE-2024-25915—22.7%
——7——CVE-2024-23223—22.7%
——7——CVE-2021-418408.2 HIG22.7%
——7An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of Functionality from an Untrusted Control Sphere.30dCVE-2025-33182—22.7%
——7——CVE-2021-418418.2 HIG22.7%
——7An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of Functionality from an Untrusted Control Sphere.30dCVE-2017-13817—22.7%
——7——CVE-2007-4570—22.7%
——7——CVE-2010-5155—22.7%
——7——CVE-2026-658328.2 HIG22.7%
——7Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so that the value following a modifier option poisons m_modifierTranslationTable, after which ServerProxy::translateKey() or ServerProxy::translateModifierMask() indexes the seven-row s_translationTable or s_masks arrays out of bounds, disclosing four bytes at an attacker-selected relative offset or crashing the connected client; an odd option count also causes an out-of-bounds OptionsList read. This issue is fixed in continuous build 1.26.0.299.21hCVE-2010-5154—22.7%
——7——CVE-2022-28762—22.7%
——7——CVE-1999-0724—22.7%
——7——CVE-2025-49192—22.7%
——7——CVE-2023-28768—22.7%
——7——CVE-2021-3717—22.7%
——7——CVE-2024-38454—22.7%
——7——CVE-2023-42937—22.7%
——7——CVE-2026-40472—22.7%
——7——CVE-2024-21286—22.7%
——7——CVE-2026-200155.8 MED22.7%
——7A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network.
This vulnerability is due to a memory leak when parsing IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to be manually reloaded.30dCVE-2024-1190—22.7%
——7——