Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,296
- High9,357
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-9524—16.4%
——5——CVE-2026-54906—16.4%
——5——CVE-2026-199336.3 MED16.4%
——5A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the function gets of the component Customer Search Module. This manipulation causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project confirms, that "it’s being processed".10dCVE-2026-116549.6 CRI16.4%
——5Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)38dCVE-2025-48248—16.4%
——5——CVE-2026-6447—16.4%
——5——CVE-2025-11577—16.4%
——5——CVE-2024-35422—16.4%
——5——CVE-2026-555348.6 HIG16.4%
——5PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network caller can invoke configured agents without credentials even when an API key was supplied. This issue is fixed in version 4.6.58.2dCVE-2025-43489—16.4%
——5——CVE-2024-50134—16.4%
——5——CVE-2017-8171—16.4%
——5——CVE-2021-42744—16.4%
——5——CVE-2019-2004—16.4%
——5——CVE-2026-543646.5 MED16.4%
——5CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to the SelectProvider.aspx endpoint. Attackers can exploit the lack of input sanitization in the custom session serialization format to inject a resellerid session variable, bypassing the IsValidRSession authentication check and gaining unauthorized access to management pages.30dCVE-2026-25234—16.4%
——5——CVE-2026-55995—16.4%
——5A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.
This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.30dCVE-2026-412876.5 MED16.4%
——5Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.19dCVE-2025-2988—16.4%
——5——CVE-2025-12438—16.4%
——5——CVE-2024-51775—16.4%
——5——CVE-2026-599817.1 HIG16.4%
——5OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.1dCVE-2025-15439—16.4%
——5——CVE-2026-4185—16.4%
——5——CVE-2025-59960—16.4%
——5——CVE-2025-10995—16.4%
——5——CVE-2026-48703—16.4%
——5——CVE-2021-33103—16.4%
——5——CVE-2025-48258—16.4%
——5——CVE-2022-45454—16.4%
——5——CVE-2022-42315—16.4%
——5——CVE-2019-10430—16.4%
——5——CVE-2017-14904—16.4%
——5——CVE-2024-4689—16.4%
——5——CVE-2024-28851—16.4%
——5——CVE-2025-48232—16.4%
——5——CVE-2025-48249—16.4%
——5——CVE-2020-7257—16.4%
——5——CVE-2025-20793—16.4%
——5——CVE-2019-5297—16.4%
——5——