Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low586
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-36610—21.9%
——7——CVE-2026-100806.5 MED21.9%
——7Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash the plugin process and deny service to all Boards users via a custom_focalboard_SUBSCRIBE_TEAM message with a non-string teamId.. Mattermost Advisory ID: MMSA-2026-0068722dCVE-2026-35572—21.9%
——7——CVE-2023-37333—21.9%
——7——CVE-2025-23001—21.9%
——7——CVE-2026-556534.3 MED21.9%
——7A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).8dCVE-2026-7899—21.9%
——7——CVE-2009-0207—21.9%
——7——CVE-2026-561456.5 MED21.9%
——7Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessive memory consumption, causing the Elasticsearch node to crash.32dCVE-2016-6450—21.9%
——7——CVE-2022-36613—21.9%
——7——CVE-2022-41284—21.9%
——7——CVE-2022-43652—21.9%
——7——CVE-2022-39997—21.9%
——7——CVE-2022-36615—21.9%
——7——CVE-2026-5512—21.9%
——7——CVE-2024-23094—21.9%
——7——CVE-2026-10748—21.9%
——7——CVE-2020-23911—21.9%
——7——CVE-2006-6655—21.9%
——7——CVE-2022-2002—21.9%
——7——CVE-2022-35104—21.9%
——7——CVE-2021-25141—21.9%
——7——CVE-2025-6722—21.9%
——7——CVE-2024-10325—21.9%
——7——CVE-2023-40153—21.9%
——7——CVE-2022-36614—21.9%
——7——CVE-2026-49230—21.9%
——7——CVE-2026-30874—21.9%
——7——CVE-2026-30836—21.9%
——7——CVE-2026-76244.3 MED21.9%
——7The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 12.4.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to invoke privileged state-changing Squirrly cloud API operations, such as revoking the site's Google Search Console and Google Analytics integrations via `api/gsc/revoke` and `api/ga/revoke`, that are otherwise restricted to administrator-level users holding the `sq_manage_settings` capability.48dCVE-2024-9421—21.9%
——7——CVE-2022-45478—21.9%
——7——CVE-2024-9271—21.9%
——7——CVE-2026-400001.8 LOW21.9%
——7The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level of ZTE File Manager. This allows unrooted devices to read files under certain system directories such as /data/data and /data/local/tmp. If access restrictions do not block untrusted applications, additional directories may also be accessible.42dCVE-2026-726876.5 MED21.9%
——7A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsearch decodes and deserializes the identifier before confirming that it was legitimately issued by the cluster, and a size value carried inside the identifier drives an allocation that is neither capped nor accounted for by the available memory-usage controls. The resulting out-of-memory condition is fatal and terminates the affected node process, resulting in a denial of service.7dCVE-2024-9445—21.9%
——7——CVE-2026-825215.3 MED21.9%
——7parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject. When the subject consists entirely of path traversal sequences, the filename sanitization function produces an empty string, and a fallback to the raw unsanitized subject causes the resulting file to be written outside the intended samples directory. An attacker who can cause a forensic failure report with a crafted Subject to be processed can write a dot-prefixed file with attacker-controlled content to an ancestor directory of the configured samples output path. Exploitation requires that file output for forensic report samples is enabled.5dCVE-2026-726476.5 MED21.9%
——7Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges on a single index can submit one specially crafted search request whose deeply nested structure is processed without a depth limit, exhausting the thread stack and terminating the affected node.7dCVE-2023-26592—21.9%
——7——