Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,289
- High9,343
- Medium5,276
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-725885.3 MED16.3%
——5A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered ones, enabling attackers to enumerate valid user accounts.1dCVE-2025-14886—16.3%
——5——CVE-2025-8400—16.3%
——5——CVE-2025-13626—16.3%
——5——CVE-2025-62656—16.3%
——5——CVE-2026-200206.8 MED16.3%
——5A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. If OSPF authentication is enabled, the attacker must know the secret key to exploit this vulnerability.
This vulnerability is due to insufficient input validation when processing OSPF update packets. An attacker could exploit this vulnerability by sending crafted OSPF update packets. A successful exploit could allow the attacker to create a buffer overflow, causing the affected device to reload, resulting in a DoS condition.18dCVE-2024-52589—16.3%
——5——CVE-2002-0065—16.3%
——5——CVE-2021-28818—16.3%
——5——CVE-2026-73557—16.3%
——5vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable, and restore state can be raced by concurrent prompt_embeds parts submitted to POST /v1/chat/completions through AsyncMultiModalItemTracker.resolve_items, asyncio.gather, and the default executor, allowing an invalid sparse tensor to reach tensor.to_dense despite the CVE-2025-62164 guard when enable_prompt_embeds is enabled. This issue is fixed in version 0.26.0.16dCVE-2025-54215—16.3%
——5——CVE-2022-31072—16.3%
——5——CVE-2025-14049—16.3%
——5——CVE-2026-182315.3 MED16.3%
——5The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.10dCVE-2026-25209—16.3%
——5——CVE-2025-14137—16.3%
——5——CVE-2021-35056—16.3%
——5——CVE-2024-36293—16.3%
——5——CVE-2025-21134—16.3%
——5——CVE-2025-59408—16.3%
——5——CVE-2025-13625—16.3%
——5——CVE-2020-28343—16.3%
——5——CVE-2025-13624—16.3%
——5——CVE-2024-50280—16.3%
——5——CVE-2021-27892—16.3%
——5——CVE-2025-54216—16.3%
——5——CVE-2020-3694—16.3%
——5——CVE-2021-29529—16.3%
——5——CVE-2014-0747—16.3%
——5——CVE-2026-45717—16.3%
——5——CVE-2021-1097—16.3%
——5——CVE-2025-62657—16.3%
——5——CVE-2019-3633—16.3%
——5——CVE-2023-529877.8 HIG16.3%
——5In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc4-mtrace: prevent underflow in sof_ipc4_priority_mask_dfs_write()
The "id" comes from the user. Change the type to unsigned to prevent
an array underflow.26dCVE-2024-0892—16.3%
——5——CVE-2026-30246—16.3%
——5——CVE-2018-11820—16.3%
——5——CVE-2024-45552—16.3%
——5——CVE-2021-4210—16.3%
——5——CVE-2025-43806—16.3%
——5——