Vulnerabilities exploitable today
369,220in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,162
- High7,749
- Medium5,663
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-37944—19.8%
——6——CVE-2017-9682—19.8%
——6——CVE-2026-46138—19.8%
——6——CVE-2024-20866—19.8%
——6——CVE-2026-33730—19.8%
——6——CVE-2025-27127—19.8%
——6——CVE-2026-12111—19.8%
——6——CVE-2026-199934.3 MED19.8%
——6A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."16dCVE-2026-0126—19.8%
——6——CVE-2025-2534—19.8%
——6——CVE-2024-50410—19.8%
——6——CVE-2024-50409—19.8%
——6——CVE-2023-44478—19.8%
——6——CVE-2025-47114—19.8%
——6——CVE-2024-37474—19.8%
——6——CVE-2024-11814—19.8%
——6——CVE-2026-31804—19.8%
——6——CVE-2024-35695—19.8%
——6——CVE-2025-43880—19.8%
——6——CVE-2025-32303—19.8%
——6——CVE-2025-15175—19.8%
——6——CVE-2025-12783—19.8%
——6——CVE-2018-3704—19.8%
——6——CVE-2026-822707.5 HIG19.8%
——6Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate provider API keys.5dCVE-2018-25131—19.8%
——6——CVE-2024-44171—19.8%
——6——CVE-2022-33160—19.8%
——6——CVE-2025-7826—19.8%
——6——CVE-2026-101564.3 MED19.8%
——6A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handle_amf_info in the library /lib/sbi/nnrf-handler.c of the component nf-instances Endpoint. Executing a manipulation of the argument nf_info_pool can lead to resource consumption. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Applying a patch is advised to resolve this issue. The issue report is flagged as already-fixed.45dCVE-2025-10527—19.8%
——6——CVE-2025-58459—19.8%
——6——CVE-2025-35433—19.8%
——6——CVE-2021-1852—19.8%
——6——CVE-2026-822687.5 HIG19.8%
——6Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses including metadata services and read retrieved content through parsed document output.8dCVE-2026-141688.8 HIG19.8%
——6A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.37dCVE-2024-57262—19.8%
——6——CVE-2026-736248.1 HIG19.8%
——6GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.23dCVE-2026-753636.8 MED19.8%
——6An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.5dCVE-2025-9199—19.8%
——6——CVE-2025-69245—19.8%
——6——