Vulnerabilities exploitable today
363,850in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,906
- High11,924
- Medium7,262
- Low683
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-40744—12.9%
——4——CVE-2026-32129—12.9%
——4——CVE-2023-24417—12.9%
——4——CVE-2026-654785.4 MED12.9%
——4Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.29dCVE-2025-32427—12.9%
——4——CVE-2026-50606.5 MED12.9%
——4The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to `wp_delete_attachment()`. This makes it possible for authenticated attackers, with Instructor-level access and above, to delete arbitrary attachments belonging to any user by enumerating sequential attachment IDs.22dCVE-2024-23233—12.9%
——4——CVE-2026-23429.3 CRI12.9%
——4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS.
This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.43dCVE-2026-1867—12.9%
——4——CVE-2025-14912—12.9%
——4——CVE-2025-66138—12.9%
——4——CVE-2025-23280—12.9%
——4——CVE-2026-534666.5 MED12.9%
——4ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.50dCVE-2024-49349—12.9%
——4——CVE-2023-32278—12.9%
——4——CVE-2026-49051—12.9%
——4——CVE-2024-32939—12.9%
——4——CVE-2026-55455—12.9%
——4——CVE-2022-50367—12.9%
——4——CVE-2024-23232—12.9%
——4——CVE-2021-33094—12.9%
——4——CVE-2022-34642—12.9%
——4——CVE-2023-1252—12.9%
——4——CVE-2026-141486.5 MED12.9%
——4Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)51dCVE-2026-667614.3 MED12.9%
——4SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.10dCVE-2023-40198—12.9%
——4——CVE-2023-48418—12.9%
——4——CVE-2011-4211—12.9%
——4——CVE-2024-44020—12.9%
——4——CVE-2022-50361—12.9%
——4——CVE-2024-45010—12.9%
——4——CVE-2023-32655—12.9%
——4——CVE-2025-26472—12.9%
——4——CVE-2023-35778—12.9%
——4——CVE-2023-34185—12.9%
——4——CVE-2026-572648.3 HIG12.9%
——4GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound.
#### setPIP command index-out-of-bound50dCVE-2023-44084—12.9%
——4——CVE-2025-65503—12.9%
——4——CVE-2023-25443—12.9%
——4——CVE-2025-66135—12.9%
——4——