Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,325
- High9,981
- Medium4,918
- Low460
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-46869—14.4%
——4——CVE-2025-34133—14.4%
——4——CVE-2026-553917.5 HIG14.4%
——4datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once in src/datamodel_code_generator/http.py through get_body, _validate_url_for_fetch, and _get_ips_from_host, but then lets httpx resolve the host again for the connection, allowing DNS rebinding to bypass allow_private_network=False and reach internal services. This issue is fixed in version 0.63.0.21dCVE-2026-542915.9 MED14.4%
——4pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.49dCVE-2026-79064—14.4%
——4——CVE-2026-24096—14.4%
——4——CVE-2026-6690—14.4%
——4——CVE-2024-13305—14.4%
——4——CVE-2026-40745—14.4%
——4——CVE-2024-23250—14.4%
——4——CVE-2025-5745—14.4%
——4——CVE-2024-32653—14.4%
——4——CVE-2026-179958.1 HIG14.4%
——4Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)24dCVE-2025-27693—14.4%
——4——CVE-2023-47613—14.4%
——4——CVE-2022-1048—14.4%
——4——CVE-2026-396255.3 MED14.4%
——4Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes TechOne techone allows Code Injection.This issue affects TechOne: from n/a through <= 3.0.3.34dCVE-2024-13292—14.4%
——4——CVE-2025-7798—14.4%
——4——CVE-2023-27558—14.4%
——4——CVE-2023-48258—14.4%
——4——CVE-2023-0191—14.4%
——4——CVE-2026-397015.3 MED14.4%
——4Missing Authorization vulnerability in Andrew ShopWP wpshopify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShopWP: from n/a through <= 5.2.4.34dCVE-2023-41972—14.4%
——4——CVE-2025-13854—14.4%
——4——CVE-2026-1099—14.4%
——4——CVE-2026-289614.6 MED14.4%
——4This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.31dCVE-2026-40395—14.4%
——4——CVE-2024-13388—14.4%
——4——CVE-2024-13237—14.4%
——4——CVE-2026-325519.3 CRI14.4%
——4Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.3dCVE-2026-443672.7 LOW14.4%
——4Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to inconsistent handling of username case sensitivity, leading to a targeted Denial of Service (DoS) and complete account lockout. This issue has been patched in version 2.10.4.36dCVE-2025-13862—14.4%
——4——CVE-2023-45083—14.4%
——4——CVE-2026-225547.8 HIG14.4%
——4MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability35dCVE-2025-56648—14.4%
——4——CVE-2026-25006—14.4%
——4——CVE-2022-48724—14.4%
——4——CVE-2021-47276—14.4%
——4——CVE-2024-13298—14.4%
——4——