Vulnerabilities exploitable today
356,426in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603
Distribution · last window
- Critical2,802
- High11,190
- Medium7,403
- Low703
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-658078.4 HIG7.5%
——2An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.33dCVE-2025-12113—7.5%
——2——CVE-2025-14489—7.5%
——2——CVE-2026-542766.1 MED7.5%
——2AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute. Further, the attacker is only receiving the digest, so should only be able to extract the user's credentials if the cryptography is weak or there is some kind of password reuse. This vulnerability is fixed in 3.14.1.38dCVE-2022-46782—7.5%
——2——CVE-2024-32893—7.5%
——2——CVE-2022-50637—7.5%
——2——CVE-2026-28915—7.5%
——2——CVE-2026-4922—7.5%
——2——CVE-2025-14491—7.5%
——2——CVE-2025-21977—7.5%
——2——CVE-2021-0508—7.5%
——2——CVE-2018-3568—7.5%
——2——CVE-2026-0959—7.5%
——2——CVE-2019-2043—7.5%
——2——CVE-2025-54526—7.5%
——2——CVE-2022-34843—7.5%
——2——CVE-2023-22444—7.5%
——2——CVE-2026-346575.5 MED7.5%
——2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in an arbitrary file system write. An attacker could leverage this vulnerability to write to unauthorized files or directories outside of intended restrictions. Exploitation of this issue requires user interaction in that a victim must extract a maliciously crafted file.15dCVE-2022-50643—7.5%
——2——CVE-2022-36864—7.5%
——2——CVE-2025-12634—7.5%
——2——CVE-2025-14490—7.5%
——2——CVE-2024-36010—7.5%
——2——CVE-2024-29210—7.5%
——2——CVE-2025-68504—7.5%
——2——CVE-2025-14262—7.5%
——2——CVE-2026-153813.7 LOW7.5%
——2The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.7dCVE-2025-386008.8 HIG7.5%
——2In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7925: fix off by one in mt7925_mcu_hw_scan()
The ssid->ssids[] and sreq->ssids[] arrays have MT7925_RNR_SCAN_MAX_BSSIDS
elements so this >= needs to be > to prevent an out of bounds access.8dCVE-2024-46485—7.5%
——2——CVE-2024-57878—7.5%
——2——CVE-2023-34332—7.5%
——2——CVE-2026-258615.9 MED7.5%
——2QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password hashing in the Tools::encrypt() function within classes/Tools.php, which concatenates a static cookie key with the supplied password. Attackers can perform offline brute-force attacks against the MD5 hashes, with the risk compounded by auto-generated 8-character passwords assigned during guest-to-customer account conversion in classes/Customer.php, making credential recovery trivial.16dCVE-2026-86048.8 HIG7.5%
——2In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.15dCVE-2025-14494—7.5%
——2——CVE-2018-9522—7.5%
——2——CVE-2023-42435—7.5%
——2——CVE-2025-68172—7.5%
——2——CVE-2017-9690—7.5%
——2——CVE-2024-13118—7.5%
——2——