Vulnerabilities exploitable today
369,638in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,121
- High7,610
- Medium5,709
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-56507—21.5%
——6——CVE-2024-28983—21.5%
——6——CVE-2025-52660—21.5%
——6——CVE-2021-24988—21.5%
——6——CVE-2025-27829—21.5%
——6——CVE-2025-701016.5 MED21.5%
——6An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before performing a binary search over extent index entries, which can result in invalid pointer calculations and an out-of-bounds memory read during extent tree traversal.48dCVE-2026-25045—21.5%
——6——CVE-2024-7888—21.4%
——6——CVE-2022-24421—21.5%
——6——CVE-2017-11747—21.4%
——6——CVE-2024-48898—21.4%
——6——CVE-2026-48904—21.4%
——6——CVE-2014-6909—21.4%
——6——CVE-2025-69430—21.4%
——6——CVE-2024-8933—21.4%
——6——CVE-2026-19683—21.4%
——6A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may obtain sensitive authentication information or interfere with DDNS update operations. Exploitation requires DDNS to be configured, communication with an external DDNS service, and attacker visibility or control of the relevant network path.
Successful exploitation may result in disclosure of DDNS account credentials, unauthorized access to DDNS management functionality, or modification of DNS records associated with the affected deployment.11dCVE-2014-7333—21.4%
——6——CVE-2026-45400—21.4%
——6——CVE-2026-749378.8 HIG21.4%
——6Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.20dCVE-2014-7011—21.4%
——6——CVE-2025-69431—21.4%
——6——CVE-2025-50859—21.4%
——6——CVE-2025-14806—21.4%
——6——CVE-2014-6994—21.4%
——6——CVE-2026-31926—21.4%
——6——CVE-2025-32260—21.4%
——6——CVE-2026-135936.5 MED21.4%
——6CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away.
The minify function has a memory leak when processing a document containing only characters to be removed, such as comments and whitespace.70dCVE-2024-39326—21.4%
——6——CVE-2023-2876—21.4%
——6——CVE-2020-4491—21.4%
——6——CVE-2014-7083—21.4%
——6——CVE-2014-7456—21.4%
——6——CVE-2026-703315.4 MED21.4%
——6Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.6dCVE-2026-10517—21.4%
——6Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is implemented entirely in github.com/quay/clair; no PSK-related code exists anywhere in claircore's codebase or git history. The unauthenticated indexer API is Clair's documented, intentional design, authentication is an opt-in deployment choice, not a code defect. No fix commit was found in claircore between the version recorded as the affected boundary (1.5.52) and the following release (1.5.53); intervening commits are unrelated dependency and feature changes, so the "fixed in 1.5.52" status is inaccurate.43dCVE-2014-6836—21.4%
——6——CVE-2026-451158.7 HIG21.4%
——6MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore list and the Select Buddies list in Private Messages pass usernames through htmlspecialchars_uni(), which may leave single quotes unescaped. The payload is triggered when a victim chooses Yes in Please Confirm while removing the username in usercp.php, or selects the username through the onclick handler in the xmlhttp.php Select Buddies popup. The uniquely identifying implementation details include Private Messages Select Buddies list, and unescaped single quotes. This issue is fixed in version 1.8.40.21dCVE-2014-7696—21.4%
——6——CVE-2022-4549—21.4%
——6——CVE-2014-6880—21.4%
——6——CVE-2014-6873—21.4%
——6——