Vulnerabilities exploitable today
367,165in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,274
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-8770—17.2%
——5——CVE-2026-53568—17.2%
——5——CVE-2024-56246—17.2%
——5——CVE-2025-46303—17.2%
——5——CVE-2024-27826—17.2%
——5——CVE-2019-5272—17.2%
——5——CVE-2021-34771—17.2%
——5——CVE-2024-400904.3 MED17.2%
——5Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Information Disclosure. An information leak in the Boa webserver allows remote, unauthenticated attackers to leak memory addresses of uClibc and the stack via sending a GET request to the index page.58dCVE-2026-1116—17.2%
——5——CVE-2024-36241—17.2%
——5——CVE-2025-7390—17.2%
——5——CVE-2026-32155—17.2%
——5——CVE-2019-5317—17.2%
——5——CVE-2026-40282—17.2%
——5——CVE-2026-557476.8 MED17.2%
——5The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Severity reflects that this affects an illustrative cookbook example rather than a core library API; applications that copy this pattern into production are affected.3dCVE-2025-63738—17.2%
——5——CVE-2026-44205—17.2%
——5——CVE-2026-65764—17.2%
——5Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.35dCVE-2026-77027—17.2%
——5Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.7dCVE-2021-27613—17.2%
——5——CVE-2026-177765.8 MED17.2%
——5Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)27dCVE-2026-393519.1 CRI17.2%
——5Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.38dCVE-2024-44183—17.2%
——5——CVE-2026-32898—17.2%
——5——CVE-2026-4830—17.2%
——5——CVE-2026-583807.3 HIG17.2%
——5A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.46dCVE-2019-19348—17.2%
——5——CVE-2025-6142—17.2%
——5——CVE-2023-38960—17.2%
——5——CVE-2024-43280—17.2%
——5——CVE-2026-6119—17.2%
——5——CVE-2024-49963—17.2%
——5——CVE-2024-33682—17.2%
——5——CVE-2024-35984—17.2%
——5——CVE-2026-248749.1 CRI17.2%
——5Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.2hCVE-2019-14399—17.2%
——5——CVE-2026-477408.1 HIG17.2%
——5Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The order detail actions cancel, mark paid, mark complete, capture payment, archive, and start processing were callable with the read-only read_orders permission and did not require edit_orders. capturePayment could trigger an actual PSP capture (real funds movement). The order shipments table actions mark delivered and edit tracking were callable with the read-only browse_orders permission. A user with read access to orders could therefore alter the lifecycle of every order in the panel and trigger real-world payment captures. This vulnerability is fixed in 2.8.0.40dCVE-2025-8551—17.2%
——5——CVE-2024-13909—17.2%
——5——CVE-2024-55907—17.2%
——5——