Vulnerabilities exploitable today
369,332in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,125
- High7,590
- Medium5,604
- Low538
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-56916—20.5%
——6——CVE-2026-1408—20.5%
——6——CVE-2025-67969—20.5%
——6——CVE-2026-25371—20.5%
——6——CVE-2026-22332—20.5%
——6——CVE-2025-29769—20.5%
——6——CVE-2025-69309—20.5%
——6——CVE-2024-41004—20.5%
——6——CVE-2025-43491—20.5%
——6——CVE-2026-619699.3 CRI20.5%
——6Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.23dCVE-2025-53636—20.5%
——6——CVE-2025-10054—20.5%
——6——CVE-2026-655089.3 CRI20.5%
——6Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.25dCVE-2025-69306—20.5%
——6——CVE-2023-43656—20.5%
——6——CVE-2026-25340—20.5%
——6——CVE-2026-54812—20.5%
——6——CVE-2026-166474.1 MED20.5%
——6Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.2dCVE-2026-728085.8 MED20.5%
——6SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint, which returns .sya PDF-annotation file content without a publish-access check. Because the endpoint is gated only by CheckAuth (unlike the /assets/* route, which enforces publish access and password), an anonymous reader (when publish authentication is disabled) or any publish RoleReader who knows an asset path can read the private PDF annotations (highlights and notes) of publish-forbidden, password-protected, or unpublished documents. The issue is limited to non-encrypted notebooks; encrypted-box annotations are not exposed.11dCVE-2026-23731—20.5%
——6——CVE-2026-42386—20.5%
——6——CVE-2026-42639—20.5%
——6——CVE-2026-556456.5 MED20.5%
——6xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client Control PDUs. During the RDP connection sequence, the parser does not perform sufficient length validation before reading specific data fields from the network stream. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted, truncated Client Control PDU. Due to missing bounds checks, the xrdp process may perform out-of-bounds memory reads, which can result in the termination of the service (Denial of Service). However, since xrdp forks a new process for each connection by default, an out-of-bounds read causing a process crash is unlikely to bring down the entire xrdp service.This issue has been fixed in version 0.10.6.1.46dCVE-2025-24136—20.5%
——6——CVE-2026-42665—20.5%
——6——CVE-2026-41339—20.5%
——6——CVE-2024-33980—20.5%
——6——CVE-2026-202688.6 HIG20.5%
——6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.23dCVE-2026-664589.3 CRI20.5%
——6Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.23dCVE-2026-32499—20.5%
——6——CVE-2026-42381—20.5%
——6——CVE-2024-46745—20.5%
——6——CVE-2026-824537.5 HIG20.5%
——6rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.8dCVE-2026-39519—20.5%
——6——CVE-2025-69310—20.5%
——6——CVE-2026-54216—20.5%
——6Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS)
vulnerability. By sending a specially crafted link including an
arbitrary path, an XSS payload or the parameter “EntryInfo”, and the
parameter “!templateName=entryMail”, an attacker can cause the payload
to execute in the victim’s browser when they click the link. This issue affects TeamDavid through Rollout 524.11dCVE-2025-69365—20.5%
——6——CVE-2020-5017—20.5%
——6——CVE-2026-54811—20.5%
——6——CVE-2026-22336—20.5%
——6——