Vulnerabilities exploitable today
368,008in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,380
- High9,625
- Medium5,570
- Low544
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-42659—18.9%
——6——CVE-2025-3100—18.9%
——6——CVE-2025-23809—18.9%
——6——CVE-2026-399687.1 HIG18.9%
——6TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution and API Authorization Bypass") is incomplete. While the builder's getCredentials tRPC endpoint was patched with workspace membership checks, the bot-engine runtime still allows any authenticated user to use credentials from any workspace via the preview chat endpoint. The bot-engine's getCredentials() utility function uses a falsy check (if (workspaceId && ...)) for workspace ownership validation. Since the preview endpoint accepts a client-controlled workspaceId field and the Zod schema allows empty strings, an attacker can supply workspaceId: "" to bypass credential ownership verification entirely. Exploitation can result in credential exfiltration, external service abuse, financial damage and a data breach.41dCVE-2022-34674—18.9%
——6——CVE-2022-49685—18.9%
——6——CVE-2024-38728—18.9%
——6——CVE-2023-526127.8 HIG18.9%
——6In the Linux kernel, the following vulnerability has been resolved:
crypto: scomp - fix req->dst buffer overflow
The req->dst buffer size should be checked before copying from the
scomp_scratch->dst to avoid req->dst buffer overflow problem.29dCVE-2026-168478.8 HIG18.9%
——6IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.9dCVE-2026-42666.7 MED18.9%
——6An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.
Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.6dCVE-2024-7756—18.9%
——6——CVE-2024-51708—18.9%
——6——CVE-2025-7667—18.9%
——6——CVE-2025-70792—18.9%
——6——CVE-2026-595658.8 HIG18.9%
——6A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.5dCVE-2024-51784—18.9%
——6——CVE-2025-36553—18.9%
——6——CVE-2024-51711—18.9%
——6——CVE-2024-51760—18.9%
——6——CVE-2025-31878—18.9%
——6——CVE-2024-51690—18.9%
——6——CVE-2024-51714—18.9%
——6——CVE-2024-51776—18.9%
——6——CVE-2024-43246—18.9%
——6——CVE-2024-51759—18.9%
——6——CVE-2025-22776—18.9%
——6——CVE-2024-51694—18.9%
——6——CVE-2025-22764—18.9%
——6——CVE-2024-37436—18.9%
——6——CVE-2019-15273—18.9%
——6——CVE-2025-46689—18.9%
——6——CVE-2023-46742—18.9%
——6——CVE-2026-394877.6 HIG18.9%
——6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.1.1.40dCVE-2025-43190—18.9%
——6——CVE-2024-51783—18.9%
——6——CVE-2026-105247.5 HIG18.9%
——6The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product prices and complete WooCommerce orders at manipulated totals.7dCVE-2025-22765—18.9%
——6——CVE-2025-40636—18.9%
——6——CVE-2026-0511—18.9%
——6——CVE-2024-51762—18.9%
——6——