Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,311
- High9,414
- Medium5,381
- Low529
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-22044—18.0%
——5——CVE-2022-49367—18.0%
——5——CVE-2026-3043—18.0%
——5——CVE-2026-337717.4 HIG18.0%
——5A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device.
The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can be verified with the menu option "Show password requirements". Failure to enforce the intended requirements can lead to weak passwords being used, which significantly increases the likelihood that an attacker can guess these and subsequently attain unauthorized access.
This issue affects CTP OS versions 9.2R1 and 9.2R2.50dCVE-2022-49433—18.0%
——5——CVE-2025-68595—18.0%
——5——CVE-2022-49498—18.0%
——5——CVE-2025-67576—18.0%
——5——CVE-2025-53674—18.0%
——5——CVE-2025-6768—18.0%
——5——CVE-2025-25872—18.0%
——5——CVE-2026-5659—18.0%
——5——CVE-2026-1643—18.0%
——5——CVE-2025-12546—18.0%
——5——CVE-2025-66088—18.0%
——5——CVE-2025-67987—18.0%
——5——CVE-2006-1167—18.0%
——5——CVE-2025-7022—18.0%
——5——CVE-2017-3741—18.0%
——5——CVE-2026-340017.8 HIG18.0%
——5A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially enabling memory corruption. This could result in a denial of service or further compromise of the system.49dCVE-2025-1284—18.0%
——5——CVE-2020-24462—18.0%
——5——CVE-2023-48772—18.0%
——5——CVE-2023-47806—18.0%
——5——CVE-2020-12385—18.0%
——5——CVE-2025-53108—18.0%
——5——CVE-2023-5626—18.0%
——5——CVE-2026-488405.3 MED18.0%
——5Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.42dCVE-2021-0394—18.0%
——5——CVE-2007-0833—18.0%
——5——CVE-2025-117313.1 LOW18.0%
——5A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.8hCVE-2026-149496.5 MED18.0%
——5A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.11dCVE-2017-5699—18.0%
——5——CVE-2007-3722—18.0%
——5——CVE-2020-12367—18.0%
——5——CVE-2024-12119—18.0%
——5——CVE-2024-27027—18.0%
——5——CVE-2025-67560—18.0%
——5——CVE-2023-3006—18.0%
——5——CVE-2024-12825—18.0%
——5——