Vulnerabilities exploitable today
359,428in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,475
- High11,085
- Medium7,046
- Low645
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-13469—10.9%
——3——CVE-2022-45155—10.9%
——3——CVE-2026-7985—10.9%
——3——CVE-2024-54434—10.9%
——3——CVE-2024-51642—10.8%
——3——CVE-2025-54154—10.9%
——3——CVE-2026-4575—10.9%
——3——CVE-2025-60948—10.9%
——3——CVE-2024-51523—10.9%
——3——CVE-2026-7553—10.9%
——3——CVE-2024-51641—10.9%
——3——CVE-2023-20065—10.9%
——3——CVE-2026-21483—10.9%
——3——CVE-2024-47021—10.9%
——3——CVE-2026-7697—10.9%
——3——CVE-2024-47120—10.9%
——3——CVE-2024-51650—10.9%
——3——CVE-2024-39876—10.9%
——3——CVE-2024-49971—10.9%
——3——CVE-2024-53051—10.9%
——3——CVE-2024-54353—10.9%
——3——CVE-2021-47716—10.9%
——3——CVE-2025-1501—10.9%
——3——CVE-2026-5643—10.9%
——3——CVE-2022-49879—10.9%
——3——CVE-2024-57493—10.9%
——3——CVE-2024-54420—10.8%
——3——CVE-2026-72952.4 LOW10.9%
——3A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.22dCVE-2026-106164.3 MED10.9%
——3A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTool.executeComplete of the file internal/tools/team_tasks_lifecycle.go of the component Team Task Completion Handler. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.23dCVE-2026-187187.0 HIG10.9%
——3Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.10dCVE-2026-7282—10.9%
——3——CVE-2024-54331—10.9%
——3——CVE-2026-7294—10.9%
——3——CVE-2023-46931—10.9%
——3——CVE-2026-33436.1 MED10.9%
——3A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.4dCVE-2026-7918—10.9%
——3——CVE-2021-33700—10.9%
——3——CVE-2026-6619—10.9%
——3——CVE-2024-31463—10.9%
——3——CVE-2024-54439—10.9%
——3——