Vulnerabilities exploitable today
359,428in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,475
- High11,085
- Medium7,046
- Low645
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-54386—10.9%
——3——CVE-2024-51642—10.8%
——3——CVE-2024-51641—10.9%
——3——CVE-2026-7553—10.9%
——3——CVE-2024-13469—10.9%
——3——CVE-2023-53977—10.9%
——3——CVE-2022-3431—10.9%
——3——CVE-2025-60948—10.9%
——3——CVE-2024-54434—10.9%
——3——CVE-2023-53978—10.9%
——3——CVE-2021-47716—10.9%
——3——CVE-2025-1501—10.9%
——3——CVE-2026-5643—10.9%
——3——CVE-2024-54414—10.9%
——3——CVE-2026-4595—10.9%
——3——CVE-2024-54436—10.9%
——3——CVE-2019-25689—10.9%
——3——CVE-2020-9129—10.9%
——3——CVE-2026-7911—10.9%
——3——CVE-2022-22558—10.9%
——3——CVE-2022-42879—10.9%
——3——CVE-2026-115544.3 MED10.9%
——3A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.23dCVE-2026-4225—10.9%
——3——CVE-2021-22509—10.9%
——3——CVE-2025-11043—10.9%
——3——CVE-2026-27910—10.9%
——3——CVE-2024-54416—10.8%
——3——CVE-2025-55735—10.9%
——3——CVE-2026-7922—10.9%
——3——CVE-2024-51645—10.9%
——3——CVE-2024-12605—10.9%
——3——CVE-2024-54435—10.9%
——3——CVE-2024-51653—10.9%
——3——CVE-2024-342687.1 HIG10.9%
——3EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers to gain full access to the device without authentication.28dCVE-2023-33898—10.8%
——3——CVE-2026-180626.4 MED10.8%
——3The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versions up to, and including, 3.7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only triggerable when the block's urlTransparent attribute is set to a non-empty value, as this is a required precondition for the vulnerable code path in build_html() to be reached.2dCVE-2023-46927—10.8%
——3——CVE-2026-48786.7 MED10.8%
——3A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.4dCVE-2024-22438—10.8%
——3——CVE-2024-58090—10.8%
——3——