Vulnerabilities exploitable today
359,665in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,517
- High11,192
- Medium7,126
- Low650
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-50198—10.9%
——3——CVE-2026-16986.1 MED10.9%
——3A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior.
This vulnerability only affects the endpoints /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback and /Authentication/Logout
of the WebClient and WebScheduler web apps.36dCVE-2018-11919—10.9%
——3——CVE-2022-24379—10.9%
——3——CVE-2015-20119—10.9%
——3——CVE-2017-14483—10.9%
——3——CVE-2022-32492—10.9%
——3——CVE-2024-55881—10.9%
——3——CVE-2023-45821—10.9%
——3——CVE-2025-4415—10.9%
——3——CVE-2025-67989—10.9%
——3——CVE-2025-30321—10.9%
——3——CVE-2026-27511—10.9%
——3——CVE-2024-6224—10.9%
——3——CVE-2025-47756—10.9%
——3——CVE-2026-41385—10.9%
——3——CVE-2025-21631—10.9%
——3——CVE-2026-356308.0 HIG10.9%
——3OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval requests without proper authorization.24dCVE-2025-42986—10.9%
——3——CVE-2025-26500—10.9%
——3——CVE-2024-56763—10.9%
——3——CVE-2023-50827—10.9%
——3——CVE-2023-22874—10.9%
——3——CVE-2024-47895—10.9%
——3——CVE-2023-26248—10.9%
——3——CVE-2026-57649—10.9%
——3——CVE-2023-27308—10.9%
——3——CVE-2022-49035—10.9%
——3——CVE-2026-34340—10.9%
——3——CVE-2023-28402—10.9%
——3——CVE-2023-41095—10.9%
——3——CVE-2025-47753—10.9%
——3——CVE-2023-40437—10.9%
——3——CVE-2024-56622—10.9%
——3——CVE-2025-1108—10.9%
——3——CVE-2024-53154—10.9%
——3——CVE-2026-16956.1 MED10.9%
——3An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication on an unknown application (unknown client_id).
This vulnerability only affects the error page of the OAuth server.36dCVE-2022-27242—10.9%
——3——CVE-2025-1161—10.9%
——3——CVE-2024-56625—10.9%
——3——