Vulnerabilities exploitable today
363,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,856
- High11,759
- Medium7,145
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-47752—13.0%
——4——CVE-2020-37164—13.0%
——4——CVE-2026-27027—13.0%
——4——CVE-2025-48145—13.0%
——4——CVE-2021-46949—13.0%
——4——CVE-2026-507665.4 MED13.0%
——4A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field (items.itemnotes).48dCVE-2021-46970—13.0%
——4——CVE-2026-162244.3 MED13.0%
——4A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The identifier of the patch is dc2b6910a423b3bfadeffaa303e1ba75cfb33900. Applying a patch is the recommended action to fix this issue.32dCVE-2025-21866—13.0%
——4——CVE-2025-54272—13.0%
——4——CVE-2026-4334—13.0%
——4——CVE-2026-450235.4 MED13.0%
——4AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes blocks without consuming any credits, regardless of the user's balance. The credit check that exists in the graph execution path (manager.py) is never reached when blocks are called directly via the external API, allowing unlimited free execution of all blocks. This vulnerability is fixed in 0.6.59.32dCVE-2025-8046—13.0%
——4——CVE-2026-24034—13.0%
——4——CVE-2025-8113—13.0%
——4——CVE-2025-68866—13.0%
——4——CVE-2025-64685—13.0%
——4——CVE-2025-47753—13.0%
——4——CVE-2025-47755—13.0%
——4——CVE-2025-61797—13.0%
——4——CVE-2024-53196—13.0%
——4——CVE-2025-31993—13.0%
——4——CVE-2024-57795—13.0%
——4——CVE-2019-5309—13.0%
——4——CVE-2026-153754.3 MED13.0%
——4A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /callrec/users_ldap.jsp of the component LDAP User Interface. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.39dCVE-2021-26332—13.0%
——4——CVE-2024-39479—13.0%
——4——CVE-2025-20382—13.0%
——4——CVE-2023-41082—13.0%
——4——CVE-2024-36952—13.0%
——4——CVE-2025-59842—13.0%
——4——CVE-2020-9202—13.0%
——4——CVE-2026-560007.8 HIG13.0%
——4Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.43dCVE-2025-62952—13.0%
——4——CVE-2025-47751—13.0%
——4——CVE-2025-68538—13.0%
——4——CVE-2025-47757—13.0%
——4——CVE-2023-44690—13.0%
——4——CVE-2024-42580—13.0%
——4——CVE-2024-2937—13.0%
——4——