Vulnerabilities exploitable today
367,165in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,274
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-51107—17.1%
——5——CVE-2017-18313—17.1%
——5——CVE-2026-483117.8 HIG17.1%
——5Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2024-13207—17.1%
——5——CVE-2025-1525—17.1%
——5——CVE-2026-483667.8 HIG17.1%
——5Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2026-22245—17.1%
——5——CVE-2025-363206.4 MED17.1%
——5IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.56dCVE-2024-10680—17.1%
——5——CVE-2026-24401—17.1%
——5——CVE-2025-47094—17.1%
——5——CVE-2020-12893—17.1%
——5——CVE-2025-1524—17.1%
——5——CVE-2025-3514—17.1%
——5——CVE-2026-585075.3 MED17.1%
——5Private Repository Existence Disclosure via go-get Meta Endpoint5dCVE-2024-42102—17.1%
——5——CVE-2023-34553—17.1%
——5——CVE-2024-27796—17.1%
——5——CVE-2024-49234—17.1%
——5——CVE-2021-34389—17.1%
——5——CVE-2024-55948—17.1%
——5——CVE-2022-4846—17.1%
——5——CVE-2024-3648—17.1%
——5——CVE-2025-14153—17.1%
——5——CVE-2022-39043—17.1%
——5——CVE-2024-40074—17.1%
——5——CVE-2019-15962—17.1%
——5——CVE-2026-482707.8 HIG17.1%
——5Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2026-483677.8 HIG17.1%
——5After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2023-27965—17.1%
——5——CVE-2024-13381—17.1%
——5——CVE-2025-1289—17.1%
——5——CVE-2026-354114.3 MED17.1%
——5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. When an administrator who has not yet configured Two-Factor Authentication (2FA) visits a crafted URL, they are presented with the legitimate Directus 2FA setup page. After completing the setup process, the application redirects the user to the attacker-controlled URL specified in the redirect parameter without any validation. This vulnerability could be used in phishing attacks targeting Directus administrators, as the initial interaction occurs on a trusted domain. This vulnerability is fixed in 11.16.1.38dCVE-2026-483707.8 HIG17.1%
——5Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2026-4208—17.1%
——5——CVE-2023-50314—17.1%
——5——CVE-2025-13245—17.1%
——5——CVE-2025-1523—17.1%
——5——CVE-2026-190656.3 MED17.1%
——5A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation causes unrestricted upload. The attack may be initiated remotely.19dCVE-2026-479767.8 HIG17.1%
——5Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4d