Vulnerabilities exploitable today
353,604in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,655
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,451
- High8,318
- Medium7,448
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-438114.7 MED4.3%
——1A race condition was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system.19hCVE-2025-0037—4.3%
——1——CVE-2026-437287.5 HIG4.3%
——1This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the Keychain.18hCVE-2025-50053—4.3%
——1——CVE-2023-21461—4.3%
——1——CVE-2026-129707.1 HIG4.3%
——1The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link.9dCVE-2025-31013—4.3%
——1——CVE-2019-256616.2 MED4.3%
——1Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer, overwriting the SEH chain and corrupting exception handlers.5dCVE-2026-10552—4.3%
——1——CVE-2022-20025—4.3%
——1——CVE-2026-548004.8 MED4.3%
——1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.20dCVE-2025-20618—4.3%
——1——CVE-2022-20449—4.3%
——1——CVE-2018-21062—4.3%
——1——CVE-2025-0688—4.3%
——1——CVE-2026-341718.0 HIG4.3%
——1Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an attacker-known invitation UUID, allowing an attacker who can cause a victim to visit the crafted invitation URL to reset the victim account password to a predictable value. This issue is fixed in version 4.0.0-beta.471.22dCVE-2026-28130—4.3%
——1——CVE-2024-39582—4.3%
——1——CVE-2026-28127—4.3%
——1——CVE-2025-527597.1 HIG4.3%
——1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS.
This issue affects Accordion FAQ: from n/a through 2.2.1.7dCVE-2026-28126—4.3%
——1——CVE-2024-27273—4.3%
——1——CVE-2021-0959—4.3%
——1——CVE-2021-0961—4.3%
——1——CVE-2019-256596.2 MED4.3%
——1ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application crash.5dCVE-2023-53242—4.3%
——1——CVE-2023-53317—4.3%
——1——CVE-2023-53285—4.3%
——1——CVE-2026-237508.1 HIG4.3%
——1Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certificate handling. server_cert_write() allocates a heap buffer of size CONFIG_POUCH_SERVER_CERT_MAX_LEN when receiving the first fragment, then appends subsequent fragments using memcpy() without verifying that sufficient capacity remains. An adjacent BLE client can send unauthenticated fragments whose combined size exceeds the allocated buffer, causing a heap overflow and crash; integrity impact is also possible due to memory corruption.15dCVE-2024-55928—4.3%
——1——CVE-2023-53280—4.3%
——1——CVE-2023-53318—4.3%
——1——CVE-2022-50330—4.3%
——1——CVE-2023-53174—4.3%
——1——CVE-2022-50431—4.3%
——1——CVE-2019-1589—4.3%
——1——CVE-2023-53375—4.3%
——1——CVE-2025-23255—4.3%
——1——CVE-2023-53275—4.3%
——1——CVE-2023-53199—4.3%
——1——