Vulnerabilities exploitable today
369,447in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,103
- High7,551
- Medium5,625
- Low543
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-49632—21.1%
——6——CVE-2023-49153—21.1%
——6——CVE-2024-35718—21.1%
——6——CVE-2024-49202—21.1%
——6——CVE-2024-41707—21.1%
——6——CVE-2022-36763—21.1%
——6——CVE-2024-49664—21.1%
——6——CVE-2018-12166—21.1%
——6——CVE-2026-7715—21.1%
——6——CVE-2024-49654—21.1%
——6——CVE-2025-60507—21.1%
——6——CVE-2026-140026.5 MED21.1%
——6Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)68dCVE-2024-40921—21.1%
——6——CVE-2024-35668—21.1%
——6——CVE-2026-628679.9 CRI21.1%
——6Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version 7.3.0 patches the issue.17dCVE-2026-3465—21.1%
——6——CVE-2026-557377.5 HIG21.1%
——6Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine.
When decoding a LARGE_TUPLE_EXT term, the validation pass decoded_size() in erts/emulator/beam/external.c reads the 32-bit arity field as unsigned (get_uint32()), while the decode pass dec_term() reads the same field as a signed 32-bit integer (get_int32()) into an int. An arity wire value of 0x80000000 passes validation as 2147483648 but decodes as -2147483648, so the subsequent hp += n moves the heap allocation pointer backward. Neither pass enforces the runtime tuple-arity limit MAX_ARITYVAL. The result is an out-of-bounds heap write; in practice the VM detects an impossible heap size and aborts, denying service. The required padding is large when uncompressed but the compressed-ETF envelope shrinks it to a small payload on the wire.
This issue affects OTP from OTP 25.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to erts from 13.0 before 17.0.4, 16.4.0.4 and 15.2.7.11.28dCVE-2024-41031—21.1%
——6——CVE-2026-40768—21.1%
——6——CVE-2026-44679—21.1%
——6——CVE-1999-1476—21.1%
——6——CVE-2024-37954—21.1%
——6——CVE-2026-33710—21.1%
——6——CVE-2025-47276—21.1%
——6——CVE-2024-41030—21.1%
——6——CVE-2024-31414—21.1%
——6——CVE-2023-3355—21.1%
——6——CVE-2022-32175—21.1%
——6——CVE-2026-762058.1 HIG21.1%
——6phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft a payload with a dangling backslash to escape the closing quote and inject arbitrary SQL commands to read sensitive database information.6dCVE-2024-35730—21.1%
——6——CVE-2023-52465—21.1%
——6——CVE-2019-15967—21.1%
——6——CVE-2026-6022—21.1%
——6——CVE-2024-41025—21.1%
——6——CVE-2026-802004.7 MED21.1%
——6Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users to attacker-controlled URLs for credential theft or phishing attacks.7dCVE-2024-41054—21.1%
——6——CVE-2026-43578—21.1%
——6——CVE-2022-46361—21.1%
——6——CVE-2026-464937.5 HIG21.1%
——6HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitable. Version 26.0.1 fixes the issue.46dCVE-2023-48768—21.1%
——6——