Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,289
- High9,343
- Medium5,276
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-73006.5 MED16.3%
——5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow.This issue affects Connext Professional: from 7.4.0 before 7.*, from 7.0.0 before 7.3.1.3, from 6.1.2 before 6.1.*.52dCVE-2020-12905—16.3%
——5——CVE-2025-32984—16.3%
——5——CVE-2025-2269—16.3%
——5——CVE-2026-413725.8 MED16.3%
——5OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authenticated browser control toward localhost endpoints and expose browser state.36dCVE-2026-25144—16.3%
——5——CVE-2026-416788.1 HIG16.3%
——5rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function will write past the end of out by in_.len() - 8 - out.len() bytes, causing an out-of-bounds write from a safe public function. This vulnerability is fixed in 0.10.78.43dCVE-2021-36342—16.3%
——5——CVE-2026-25767—16.3%
——5——CVE-2026-646644.3 MED16.3%
——5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.22dCVE-2026-12440—16.3%
——5——CVE-2024-56534—16.3%
——5——CVE-2024-414465.4 MED16.3%
——5A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.55dCVE-2026-30246—16.3%
——5——CVE-2021-1097—16.3%
——5——CVE-2025-62657—16.3%
——5——CVE-2026-200206.8 MED16.3%
——5A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. If OSPF authentication is enabled, the attacker must know the secret key to exploit this vulnerability.
This vulnerability is due to insufficient input validation when processing OSPF update packets. An attacker could exploit this vulnerability by sending crafted OSPF update packets. A successful exploit could allow the attacker to create a buffer overflow, causing the affected device to reload, resulting in a DoS condition.18dCVE-2019-3633—16.3%
——5——CVE-2023-529877.8 HIG16.3%
——5In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc4-mtrace: prevent underflow in sof_ipc4_priority_mask_dfs_write()
The "id" comes from the user. Change the type to unsigned to prevent
an array underflow.26dCVE-2021-28820—16.3%
——5——CVE-2025-14886—16.3%
——5——CVE-2026-25208—16.3%
——5——CVE-2025-8400—16.3%
——5——CVE-2024-40938—16.3%
——5——CVE-2025-5984—16.3%
——5——CVE-2021-31833—16.3%
——5——CVE-2024-57926—16.3%
——5——CVE-2023-6176—16.3%
——5——CVE-2025-13626—16.3%
——5——CVE-2025-54218—16.3%
——5——CVE-2025-39484—16.3%
——5——CVE-2021-28818—16.3%
——5——CVE-2021-43668—16.3%
——5——CVE-2002-0065—16.3%
——5——CVE-2020-24509—16.3%
——5——CVE-2026-8560—16.3%
——5——CVE-2024-52589—16.3%
——5——CVE-2025-13622—16.3%
——5——CVE-2025-54216—16.3%
——5——CVE-2021-27892—16.3%
——5——