Vulnerabilities exploitable today
351,929in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical1,913
- High6,189
- Medium5,025
- Low479
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-20458—2.5%
——1——CVE-2025-62276—2.5%
——1——CVE-2023-29146—2.5%
——1——CVE-2024-23366—2.5%
——1——CVE-2022-32609—2.5%
——1——CVE-2025-5141—2.5%
——1——CVE-2025-31459—2.5%
——1——CVE-2026-37526—2.5%
——1——CVE-2026-28615—2.5%
——1——CVE-2025-68340—2.5%
——1——CVE-2026-48028—2.5%
——1——CVE-2024-25988—2.5%
——1——CVE-2022-49967—2.5%
——1——CVE-2024-38798—2.5%
——1——CVE-2024-20022—2.5%
——1——CVE-2026-23080—2.5%
——1——CVE-2026-27659—2.5%
——1——CVE-2024-23599—2.5%
——1——CVE-2025-64760—2.5%
——1——CVE-2025-31440—2.5%
——1——CVE-2022-32610—2.5%
——1——CVE-2026-480226.5 MED2.5%
——1@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port, so credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP downgrades, allowing a co-tenant on an adjacent port or a network-position attacker capable of forging a redirect to capture bearer tokens, session cookies, and proxy credentials and impersonate the victim against the upstream service. This issue is fixed in version 18.1.2.3dCVE-2024-8375—2.5%
——1——CVE-2026-34382—2.5%
——1——CVE-2025-33196—2.5%
——1——CVE-2025-711145.5 MED2.5%
——1In the Linux kernel, the following vulnerability has been resolved:
via_wdt: fix critical boot hang due to unnamed resource allocation
The VIA watchdog driver uses allocate_resource() to reserve a MMIO
region for the watchdog control register. However, the allocated
resource was not given a name, which causes the kernel resource tree
to contain an entry marked as "<BAD>" under /proc/iomem on x86
platforms.
During boot, this unnamed resource can lead to a critical hang because
subsequent resource lookups and conflict checks fail to handle the
invalid entry properly.9dCVE-2026-560246.5 MED2.5%
——1Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery.
This issue affects WP EasyPay: from n/a through 4.5.0.22dCVE-2024-23362—2.5%
——1——CVE-2026-23146—2.5%
——1——CVE-2025-64498—2.5%
——1——CVE-2025-32022—2.5%
——1——CVE-2026-43032—2.5%
——1——CVE-2026-23063—2.5%
——1——CVE-2019-25476—2.5%
——1——CVE-2026-23467—2.5%
——1——CVE-2025-156665.3 MED2.5%
——1A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function Assimp::SceneCombiner::Copy of the file code/Common/SceneCombiner.cpp of the component Model File Handler. Such manipulation of the argument width/height leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. This and similar defects are tracked and handled via issue #6128.22dCVE-2019-25469—2.5%
——1——CVE-2023-33833—2.5%
——1——CVE-2025-67719—2.5%
——1——CVE-2026-21488—2.5%
——1——