Vulnerabilities exploitable today
369,447in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,103
- High7,551
- Medium5,627
- Low543
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-66397—21.0%
——6——CVE-2025-1491—21.0%
——6——CVE-2026-7579—21.0%
——6——CVE-2024-9452—21.0%
——6——CVE-2026-30662—21.0%
——6——CVE-2026-58327.3 HIG21.0%
——6A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.45dCVE-2024-33471—21.0%
——6——CVE-2024-10479—21.0%
——6——CVE-2023-4942—21.0%
——6——CVE-2026-835968.8 HIG21.0%
——6A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.3dCVE-2025-69415—21.0%
——6——CVE-2025-703648.8 HIG21.0%
——6An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. NOTE: the Supplier's position is that this is "a historical and intended administrative feature of the product, accessible only to already authenticated users explicitly granted administrator privileges." However, restrictions on some PHP functions were added in 8.4.64dCVE-2026-629097.8 HIG21.0%
——6Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.24dCVE-2024-55578—21.0%
——6——CVE-2026-23817—21.0%
——6——CVE-2024-54444—21.0%
——6——CVE-2021-30815—21.0%
——6——CVE-2024-45451—21.0%
——6——CVE-2026-114747.3 HIG21.0%
——6A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown function of the file service/RegisterService.php of the component Registration Endpoint. Performing a manipulation of the argument stimg results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.46dCVE-2024-45452—21.0%
——6——CVE-2023-4926—21.0%
——6——CVE-2017-5695—21.0%
——6——CVE-2023-47651—21.0%
——6——CVE-2026-32972—21.0%
——6——CVE-2023-2007—21.0%
——6——CVE-2023-32355—21.0%
——6——CVE-2026-4089—21.0%
——6——CVE-2026-33724—21.0%
——6——CVE-2026-34525—21.0%
——6——CVE-2025-32115—21.0%
——6——CVE-2026-770099.9 CRI21.0%
——6The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.4dCVE-2025-65519—21.0%
——6——CVE-2021-47092—21.0%
——6——CVE-2023-46074—21.0%
——6——CVE-2026-746498.8 HIG21.0%
——6In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix missing shared-key auth challenge length check
The WEP shared-key authentication handler uses the challenge-text
element's attacker-controlled length without checking it against the
fixed 128-byte chg_txt buffer.
In OnAuthClient() the length from rtw_get_ie() - up to 255 - is used
to perform memcpy() into the 128-byte pmlmeinfo->chg_txt, so a
malicious AP sending a malformed WLAN_EID_CHALLENGE element can
overflow/underfill chg_txt by up to 127 bytes. It is reachable over the
air, before association, during shared-key authentication. In the case
of an overflow, the driver can write out of bounds. In the case of an
underfill, the driver can echo stale buffer memory.
The challenge text is defined to be exactly 128 octets, which is
already provided as the WLAN_AUTH_CHALLENGE_LEN define; require the
element to be exactly that length before use.13dCVE-2026-95627.3 HIG21.0%
——6A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. Multiple endpoints are affected. The project was informed of the problem early through an issue report but has not responded yet.46dCVE-2024-49868—21.0%
——6——CVE-2022-4318—21.0%
——6——CVE-2025-1440—21.0%
——6——CVE-2024-13858—21.0%
——6——