Vulnerabilities exploitable today
368,008in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,380
- High9,630
- Medium5,583
- Low545
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-9430—18.9%
——6——CVE-2024-51782—18.9%
——6——CVE-2026-595377.6 HIG18.9%
——6Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.37dCVE-2024-41594—18.9%
——6——CVE-2024-51706—18.9%
——6——CVE-2024-43241—18.9%
——6——CVE-2024-51689—18.9%
——6——CVE-2025-13148—18.9%
——6——CVE-2024-51717—18.9%
——6——CVE-2024-51691—18.9%
——6——CVE-2024-51716—18.9%
——6——CVE-2024-49308—18.9%
——6——CVE-2026-54215—18.9%
——6Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the
“replyUrl” parameter. An attacker can exploit this vulnerability to
craft a URL within the application that, when visited, redirects the
user’s browser to an arbitrary third-party site. This can be abused for
phishing attacks, where users receive a trusted domain link but are
redirected to a phishing website. This issue affects TeamDavid through Rollout 524.7dCVE-2026-23148—18.9%
——6——CVE-2025-687998.1 HIG18.9%
——6In the Linux kernel, the following vulnerability has been resolved:
caif: fix integer underflow in cffrml_receive()
The cffrml_receive() function extracts a length field from the packet
header and, when FCS is disabled, subtracts 2 from this length without
validating that len >= 2.
If an attacker sends a malicious packet with a length field of 0 or 1
to an interface with FCS disabled, the subtraction causes an integer
underflow.
This can lead to memory exhaustion and kernel instability, potential
information disclosure if padding contains uninitialized kernel memory.
Fix this by validating that len >= 2 before performing the subtraction.34dCVE-2024-51759—18.9%
——6——CVE-2025-22764—18.9%
——6——CVE-2025-53935—18.9%
——6——CVE-2024-37436—18.9%
——6——CVE-2026-770835.9 MED18.9%
——6n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's Function.prototype, allowing an authenticated user with the ability to create and execute workflows to pollute it from within a Code node execution and recover a reference to the host's globalThis, resulting in a sandbox escape. The full exploit chain additionally depends on specific modules being available as allowlisted imports in the deployment's configuration. The issue is fixed in versions 1.123.69, 2.33.4, and 2.34.1.19hCVE-2023-46742—18.9%
——6——CVE-2024-51710—18.9%
——6——CVE-2025-58079—18.9%
——6——CVE-2024-51761—18.9%
——6——CVE-2025-22793—18.9%
——6——CVE-2020-4980—18.9%
——6——CVE-2024-51695—18.9%
——6——CVE-2025-10870—18.9%
——6——CVE-2024-51690—18.9%
——6——CVE-2025-31878—18.9%
——6——CVE-2026-3711—18.9%
——6——CVE-2024-51719—18.9%
——6——CVE-2024-51711—18.9%
——6——CVE-2025-63029—18.9%
——6——CVE-2024-51705—18.9%
——6——CVE-2026-3710—18.9%
——6——CVE-2024-51763—18.9%
——6——CVE-2026-54218—18.9%
——6Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various
files using only obfuscation. Any user with access to the server’s file
system, or who can otherwise extract files from the server (see
vulnerability “Random File Read”), can potentially obtain affected
users’ passwords. This issue affects TeamDavid through Rollout 524.7dCVE-2022-33747—18.9%
——6——CVE-2025-46545—18.9%
——6——