Vulnerabilities exploitable today
369,598in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,115
- High7,606
- Medium5,692
- Low556
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2009-3482—21.3%
——6——CVE-2024-13838—21.3%
——6——CVE-2024-35475—21.3%
——6——CVE-2024-13404—21.3%
——6——CVE-2026-544216.8 MED21.3%
——6In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.47dCVE-2026-395015.3 MED21.3%
——6Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through <= 1.4.5.45dCVE-2025-46931—21.3%
——6——CVE-2026-515838.5 HIG21.3%
——6An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.7dCVE-2024-40919—21.3%
——6——CVE-2022-49389—21.3%
——6——CVE-2022-49307—21.3%
——6——CVE-2018-6261—21.3%
——6——CVE-2025-5801—21.3%
——6——CVE-2026-186546.8 MED21.3%
——6Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint.
To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.34dCVE-2025-46894—21.3%
——6——CVE-2026-42760—21.3%
——6——CVE-2025-12815—21.3%
——6——CVE-2026-4509—21.3%
——6——CVE-2026-5029—21.3%
——6——CVE-2025-68027—21.3%
——6——CVE-1999-0484—21.3%
——6——CVE-2025-34246—21.3%
——6——CVE-2026-114907.3 HIG21.3%
——6A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.47dCVE-2026-494288.4 HIG21.3%
——6Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this.
An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.6dCVE-2024-1153—21.3%
——6——CVE-2024-47360—21.3%
——6——CVE-2025-46977—21.3%
——6——CVE-2025-46895—21.3%
——6——CVE-2026-5008610.0 CRI21.3%
——6The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).60dCVE-2025-46914—21.3%
——6——CVE-2024-33009—21.3%
——6——CVE-2025-156646.8 MED21.3%
——6The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.4dCVE-2025-9137—21.3%
——6——CVE-2025-46975—21.3%
——6——CVE-2025-46972—21.3%
——6——CVE-2020-4787—21.3%
——6——CVE-2001-1405—21.3%
——6——CVE-2025-46910—21.3%
——6——CVE-2020-5362—21.3%
——6——CVE-2025-46920—21.3%
——6——