Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,357
- Medium5,357
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-11272—17.8%
——5——CVE-2026-1391—17.8%
——5——CVE-2021-44828—17.8%
——5——CVE-2026-3225—17.8%
——5——CVE-2026-482893.5 LOW17.8%
——5Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.5dCVE-2023-46280—17.8%
——5——CVE-2022-41650—17.8%
——5——CVE-2025-49920—17.8%
——5——CVE-2025-1910—17.8%
——5The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed.25dCVE-2024-30148—17.8%
——5——CVE-2025-30747—17.8%
——5——CVE-2025-68999—17.8%
——5——CVE-2026-55883—17.8%
——5Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebSocket at /ws/view is gated by a CSRF token, but the token is served by the unauthenticated /api/websocket_token endpoint and the upgrader accepts clients that omit an Origin header. When the HUD is network-exposed, an attacker who can reach the listener can open the HUD WebSocket and receive the full view stream, including session state, Tiltfile contents, resource statuses, and continued updates. This issue is fixed in version 0.37.4.49dCVE-2026-502662.2 LOW17.8%
——5In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018).41dCVE-2026-34984—17.8%
——5——CVE-2025-7105—17.8%
——5——CVE-2026-24817—17.8%
——5——CVE-2024-43186—17.8%
——5——CVE-2026-42730—17.8%
——5——CVE-2024-22069—17.8%
——5——CVE-2025-15055—17.8%
——5——CVE-2024-35709—17.8%
——5——CVE-2022-49258—17.8%
——5——CVE-2025-2279—17.8%
——5——CVE-2026-135969.1 CRI17.8%
——5The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.6dCVE-2026-492019.8 CRI17.8%
——5The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.42dCVE-2025-7964—17.8%
——5——CVE-2022-46142—17.7%
——5——CVE-2025-5116—17.7%
——5——CVE-2022-42259—17.7%
——5——CVE-2022-21416—17.7%
——5——CVE-2024-31574—17.7%
——5——CVE-2017-7496—17.7%
——5——CVE-2026-483467.9 HIG17.7%
——5Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.5dCVE-2020-37022—17.7%
——5——CVE-2026-2160—17.7%
——5——CVE-2022-21375—17.7%
——5——CVE-2026-32629—17.7%
——5——CVE-2026-40837—17.7%
——5——CVE-2025-9569—17.7%
——5——