Vulnerabilities exploitable today
369,575in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,111
- High7,598
- Medium5,690
- Low556
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-9720—21.1%
——6——CVE-2024-13802—21.1%
——6——CVE-2024-13757—21.1%
——6——CVE-2025-2940—21.1%
——6——CVE-2024-20713—21.1%
——6——CVE-2005-3289—21.1%
——6——CVE-2021-3741—21.1%
——6——CVE-2024-12452—21.1%
——6——CVE-2024-13395—21.1%
——6——CVE-2026-4066—21.1%
——6——CVE-2025-1410—21.1%
——6——CVE-2025-55340—21.1%
——6——CVE-2025-504917.1 HIG21.1%
——6Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.64dCVE-2026-49776—21.1%
——6——CVE-2024-8893—21.1%
——6——CVE-2024-45878—21.1%
——6——CVE-2022-27672—21.1%
——6——CVE-2026-151536.8 MED21.1%
——6The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks.39dCVE-2022-49647—21.1%
——6——CVE-2026-91866.5 MED21.1%
——6IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).3dCVE-2024-4783—21.1%
——6——CVE-2026-49067—21.1%
——6——CVE-2024-52066—21.1%
——6——CVE-2026-19472—21.1%
——6A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability6dCVE-2025-0811—21.1%
——6——CVE-2022-26369—21.1%
——6——CVE-2022-0444—21.1%
——6——CVE-2026-579525.3 MED21.1%
——6Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verify payload ownership. An operator in one operation can invoke these endpoints with a known payload UUID from another operation to access that operation's C2 profile configuration including encryption keys and callback parameters.55dCVE-2022-38095—21.1%
——6——CVE-2026-739325.3 MED21.1%
——6Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).10dCVE-2024-44039—21.1%
——6——CVE-2022-34520—21.1%
——6——CVE-2026-666599.3 CRI21.1%
——6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection.
This issue affects Tablesome Table: from n/a through 1.2.9.26dCVE-2022-495337.8 HIG21.1%
——6In the Linux kernel, the following vulnerability has been resolved:
ath11k: Change max no of active probe SSID and BSSID to fw capability
The maximum number of SSIDs in a for active probe requests is currently
reported as 16 (WLAN_SCAN_PARAMS_MAX_SSID) when registering the driver.
The scan_req_params structure only has the capacity to hold 10 SSIDs.
This leads to a buffer overflow which can be triggered from
wpa_supplicant in userspace. When copying the SSIDs into the
scan_req_params structure in the ath11k_mac_op_hw_scan route, it can
overwrite the extraie pointer.
Firmware supports 16 ssid * 4 bssid, for each ssid 4 bssid combo probe
request will be sent, so totally 64 probe requests supported. So
set both max ssid and bssid to 16 and 4 respectively. Remove the
redundant macros of ssid and bssid.
Tested-on: IPQ8074 hw2.0 AHB WLAN.HK.2.7.0.1-01300-QCAHKSWPL_SILICONZ-134dCVE-2020-0559—21.1%
——6——CVE-2021-47773—21.1%
——6——CVE-2026-58838.8 HIG21.1%
——6Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)46dCVE-2019-8682—21.1%
——6——CVE-2024-48312—21.1%
——6——CVE-2019-19096—21.1%
——6——