Vulnerabilities exploitable today
354,689in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,617
- High9,374
- Medium7,592
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-38055—5.4%
——2——CVE-2025-38272—5.4%
——2——CVE-2026-35380—5.4%
——2——CVE-2024-13580—5.4%
——2——CVE-2023-28207—5.4%
——2——CVE-2026-7977—5.4%
——2——CVE-2024-41686—5.4%
——2——CVE-2025-58990—5.4%
——2——CVE-2025-20954—5.4%
——2——CVE-2026-162112.6 LOW5.4%
——2A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation Handler. Executing a manipulation of the argument counter can lead to race condition. Attacks of this nature are highly complex. The exploitability is said to be difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.12dCVE-2025-38626—5.4%
——2——CVE-2026-285273.5 LOW5.4%
——2BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAYER_APPLICATION_SETTING_ATTRIBUTE_TEXT and GET_PLAYER_APPLICATION_SETTING_VALUE_TEXT handlers that allows nearby attackers to read beyond packet boundaries. Attackers can establish a paired Bluetooth Classic connection and send specially crafted VENDOR_DEPENDENT responses to trigger out-of-bounds reads, causing information disclosure and potential crashes on affected devices.18dCVE-2022-50046—5.4%
——2——CVE-2023-24465—5.3%
——2——CVE-2025-9732—5.4%
——2——CVE-2025-20937—5.4%
——2——CVE-2025-9622—5.4%
——2——CVE-2025-0976—5.4%
——2——CVE-2026-346116.5 MED5.4%
——2WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to send HTML emails to every registered user on the platform. While the endpoint verifies admin session status, it does not validate a CSRF token. Because AVideo sets SameSite=None on session cookies, a cross-origin POST request from an attacker-controlled page will include the admin's session cookie automatically. An attacker who lures an admin to a malicious page can send an arbitrary HTML email to every user on the platform, appearing to originate from the instance's legitimate SMTP address. At time of publication, there are no publicly available patches.8dCVE-2024-47972—5.4%
——2——CVE-2026-409715.0 MED5.4%
——2When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.8dCVE-2024-45676—5.4%
——2——CVE-2022-50009—5.4%
——2——CVE-2021-22421—5.4%
——2——CVE-2025-66523—5.4%
——2——CVE-2025-38441—5.4%
——2——CVE-2025-10215—5.4%
——2——CVE-2025-32899—5.4%
——2——CVE-2025-20948—5.4%
——2——CVE-2022-50060—5.4%
——2——CVE-2011-2343—5.4%
——2——CVE-2025-38410—5.4%
——2——CVE-2023-33079—5.4%
——2——CVE-2026-2538—5.4%
——2——CVE-2022-50048—5.4%
——2——CVE-2022-50056—5.4%
——2——CVE-2025-38033—5.4%
——2——CVE-2025-38644—5.4%
——2——CVE-2025-38645—5.4%
——2——CVE-2025-4386—5.4%
——2——