Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,357
- Medium5,357
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-29801—17.7%
——5——CVE-2026-13202—17.7%
——5A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation.
This issue affects Opentext Directory Services: through 22.2.15dCVE-2025-56514—17.7%
——5——CVE-2026-646379.9 CRI17.7%
——5Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.25dCVE-2007-3635—17.7%
——5——CVE-2024-41734—17.7%
——5——CVE-2024-47310—17.7%
——5——CVE-2026-44371—17.7%
——5——CVE-2026-2079—17.7%
——5——CVE-2026-16881—17.7%
——5A code injection vulnerability exists in the LINE Android app prior to version 26.7.2.
The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates.
As a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile.
A server-side mitigation has been deployed that also protects existing Android clients that have not been updated to version 26.7.2.4dCVE-2025-9815—17.7%
——5——CVE-2025-54343—17.7%
——5——CVE-2024-44025—17.7%
——5——CVE-2026-10097—17.7%
——5——CVE-2025-9191—17.7%
——5——CVE-2017-18293—17.7%
——5——CVE-2026-27496—17.7%
——5——CVE-2024-32785—17.7%
——5——CVE-2022-32925—17.7%
——5——CVE-2025-11080—17.7%
——5——CVE-2017-20015—17.7%
——5——CVE-2024-58273—17.7%
——5——CVE-2021-29741—17.7%
——5——CVE-2026-35041—17.7%
——5——CVE-2025-459396.5 MED17.7%
——5Apwide Golive 10.2.0 Jira plugin allows Server-Side Request Forgery (SSRF) via the test webhook function.59dCVE-2026-464475.8 MED17.7%
——5OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.41dCVE-2026-2076—17.7%
——5——CVE-2024-44027—17.7%
——5——CVE-2025-43788—17.7%
——5——CVE-2023-47791—17.6%
——5——CVE-2022-32857—17.7%
——5——CVE-2019-25462—17.7%
——5——CVE-2017-202478.2 HIG17.7%
——5WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid parameter. Attackers can send GET requests with crafted SQL payloads in the aid parameter to extract sensitive database information including user credentials and table contents.42dCVE-2024-27871—17.7%
——5——CVE-2025-24112—17.7%
——5——CVE-2025-54607—17.7%
——5——CVE-2025-8487—17.7%
——5——CVE-2025-49485—17.7%
——5——CVE-2024-47172—17.7%
——5——CVE-2019-25433—17.7%
——5——