Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-556586.5 MED21.9%
——7GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media_tools/av_parsers.c). bThis vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.48dCVE-2023-23473—21.9%
——7——CVE-2025-66360—21.9%
——7——CVE-2026-6957—21.9%
——7——CVE-2026-632299.1 CRI21.9%
——7A pre-authentication blind SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
the SSO OAuth endpoint to read sensitive database contents, including
personally identifiable information, credentials, and valid JWT tokens that may
enable account takeover.40dCVE-2025-25235—21.9%
——7——CVE-2024-46892—21.9%
——7——CVE-2025-56466—21.9%
——7——CVE-2024-41824—21.9%
——7——CVE-2024-39023—21.9%
——7——CVE-2024-44033—21.9%
——7——CVE-2025-53458—21.9%
——7——CVE-2026-726526.5 MED21.9%
——7Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable.6dCVE-2025-48445—21.9%
——7——CVE-2026-630956.5 MED21.9%
——7Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership verification. Attackers can exploit the unverified Forget3PID handler to remove a victim's email or MSISDN binding and subsequently rebind the address through an identity server to hijack the victim's password reset flow.53dCVE-2025-36247—21.9%
——7——CVE-2008-0217—21.9%
——7——CVE-2026-692787.8 HIG21.9%
——7Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.6dCVE-2026-39530—21.9%
——7——CVE-2026-34375—21.9%
——7——CVE-2025-57950—21.9%
——7——CVE-2026-2547—21.9%
——7——CVE-2021-22573—21.9%
——7——CVE-2024-44032—21.9%
——7——CVE-2025-31544—21.9%
——7——CVE-2025-8942—21.9%
——7——CVE-2025-57941—21.9%
——7——CVE-2026-33080—21.9%
——7——CVE-2026-99768.8 HIG21.9%
——7Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)50dCVE-2023-20089—21.9%
——7——CVE-2025-27298—21.9%
——7——CVE-2021-23827—21.9%
——7——CVE-2021-32000—21.9%
——7——CVE-2026-27044—21.9%
——7——CVE-2026-763447.7 HIG21.9%
——7In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write dispatch metadata to an arbitrary location on the host by supplying a crafted search identifier to a Representational State Transfer (REST) API endpoint and affect system integrity on the host. The vulnerability is possible because Splunk Enterprise does not validate the search identifier before using it to create a dispatch directory. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.18dCVE-2022-39071—21.9%
——7——CVE-2026-193594.7 MED21.9%
——7A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this issue. Upgrading the affected component is advised. The project explains: "The reported IAM permission configuration is a known historical issue that was already addressed in 2024, beginning with GoldVIP version 1.13.0. The permissions were updated in subsequent releases, including version 1.15.0. In addition, we also sent a request to either update or deprecate the older release in the AWS SAR application repository."27dCVE-2026-593206.5 MED21.9%
——7When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and the broker stops delivering, leaving the listener silently stalled while isRunning() remains true.
Spring AMQP 4.1.08dCVE-2025-63662—21.9%
——7——CVE-2025-55049—21.9%
——7——