Vulnerabilities exploitable today
366,910in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,352
- Medium5,308
- Low510
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-61608—16.8%
——5——CVE-2022-45121—16.8%
——5——CVE-2023-25065—16.8%
——5——CVE-2025-1235—16.8%
——5——CVE-2022-36839—16.8%
——5——CVE-2022-41696—16.8%
——5——CVE-2018-7989—16.8%
——5——CVE-2026-75735.0 MED16.8%
——5An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parameters via a network request.37dCVE-2023-45190—16.8%
——5——CVE-2025-66141—16.8%
——5——CVE-2025-66142—16.8%
——5——CVE-2026-22170—16.8%
——5——CVE-2022-0264—16.8%
——5——CVE-2007-5847—16.8%
——5——CVE-2026-363876.5 MED16.8%
——5A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE.56dCVE-2026-34426.1 MED16.8%
——5A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.8dCVE-2023-49883—16.8%
——5——CVE-2026-99227.5 HIG16.8%
——5Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)41dCVE-2022-42833—16.8%
——5——CVE-2023-23532—16.8%
——5——CVE-2024-36489—16.8%
——5——CVE-2025-24598—16.8%
——5——CVE-2025-10868—16.8%
——5——CVE-2015-1865—16.8%
——5——CVE-2026-780576.3 MED16.8%
——5A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the component Management Mutation Handler. This manipulation of the argument roll_no/name/father_name/class/mobile/email/password/remark causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.6dCVE-2024-26973—16.8%
——5——CVE-2024-42124—16.8%
——5——CVE-2025-9326—16.8%
——5——CVE-2026-212925.4 MED16.8%
——5Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.2dCVE-2026-56066.3 MED16.8%
——5A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /order-details.php of the component Parameter Handler. The manipulation of the argument orderid results in sql injection. It is possible to launch the attack remotely.37dCVE-2025-11131—16.8%
——5——CVE-2024-35137—16.8%
——5——CVE-2026-663824.3 MED16.8%
——5An authenticated user may write files outside the intended Artifactory work directory under specific conditions.2dCVE-2026-655428.8 HIG16.8%
——5Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.18dCVE-2025-9826—16.8%
——5——CVE-2025-8552—16.8%
——5——CVE-2020-12729—16.8%
——5——CVE-2026-40946—16.8%
——5——CVE-2026-27631—16.8%
——5——CVE-2026-39971—16.8%
——5——