Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-22914—21.9%
——7——CVE-2026-34746—21.9%
——7——CVE-2024-29177—21.9%
——7——CVE-2026-506507.8 HIG21.9%
——7Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.46dCVE-2026-726636.5 MED21.9%
——7Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the input. Because the evaluation runs synchronously, a single request consumes the Kibana request-processing thread indefinitely, and Kibana stops responding to all further requests until the service is restarted.6dCVE-2026-76651—21.9%
——7A buffer
overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing
multipart/form-data requests. Insufficient validation of an attacker-controlled
boundary parameter may allow a remote unauthenticated attacker to submit a
crafted request that corrupts memory by overwriting data beyond the bounds of
an internal buffer.
Successful
exploitation may result in modification or corruption of process memory,
potentially leading to undefined application behavior. Arbitrary code
execution, information disclosure, and denial-of-service conditions have not
been demonstrated.7dCVE-2025-57904—21.9%
——7——CVE-2025-14016—21.9%
——7——CVE-2025-67950—21.9%
——7——CVE-2025-3502—21.9%
——7——CVE-2024-36041—21.9%
——7——CVE-2024-52032—21.9%
——7——CVE-2024-44390—21.9%
——7——CVE-2022-33928—21.9%
——7——CVE-2026-726396.5 MED21.9%
——7Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker. An authenticated user holding only read privileges on a single searchable index can submit one small search request that causes the node to reserve an excessively large internal data structure. The allocation occurs before the existing highlighting safety limits are evaluated, so memory exhaustion raises a fatal error that terminates the Elasticsearch node process. This results in a denial of service for the affected node and degrades cluster routing and health. The defect is not volumetric and does not depend on the size of the indexed data, so a single request is sufficient.7dCVE-2025-57906—21.9%
——7——CVE-2023-7113—21.9%
——7——CVE-2025-10367—21.9%
——7——CVE-2025-57940—21.9%
——7——CVE-2026-167367.5 HIG21.9%
——7The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.13dCVE-2020-7565—21.9%
——7——CVE-2018-19948—21.9%
——7——CVE-2025-54822—21.9%
——7——CVE-2024-13047—21.9%
——7——CVE-2025-33225—21.9%
——7——CVE-2026-152109.1 CRI21.9%
——7The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.13dCVE-2009-4191—21.9%
——7——CVE-2024-23851—21.9%
——7——CVE-2005-2196—21.9%
——7——CVE-2025-59955—21.9%
——7——CVE-2025-67921—21.9%
——7——CVE-2026-650818.1 HIG21.9%
——7NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.7dCVE-2026-789533.1 LOW21.9%
——7Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)11dCVE-2021-43777—21.9%
——7——CVE-2026-726386.5 MED21.9%
——7Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a single request containing a specially crafted, malformed custom analysis definition that is resolved recursively without a cycle or depth check, exhausting the thread stack and terminating the affected node.7dCVE-2024-34029—21.9%
——7——CVE-2023-26286—21.9%
——7——CVE-2026-32128—21.9%
——7——CVE-2025-59792—21.9%
——7——CVE-2024-13046—21.9%
——7——