Vulnerabilities exploitable today
351,720in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,651
New KEV · 24H0
Exploit Today ≥ 701,587
Distribution · last window
- Critical1,750
- High5,599
- Medium4,484
- Low405
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-44310—1.6%
——0——CVE-2025-58322—1.6%
——0——CVE-2025-7005—1.6%
——0——CVE-2025-10491—1.6%
——0——CVE-2024-561415.0 MED1.6%
——0Minosoft is an open-source, multi-version Minecraft Java Edition client written in Kotlin. Starting in commit f1ae30e2b046a490026a8413b075685deb795122, the CryptManager encryption routine ( CryptManager.kt ) initializes its AES cipher using an initialization vector (IV) that is set equal to the secret key rather than to a sufficiently random value. Because the IV is not random and is derived directly from the key, the encryption is vulnerable to chosen-ciphertext/chosen-plaintext attacks: an attacker who can submit specific messages for encryption can recover the secret key. This affects all versions supporting Minecraft protocol 1.7 and later. No patched version is available, and no known workarounds are available.13dCVE-2021-0997—1.6%
——0——CVE-2023-32868—1.6%
——0——CVE-2021-39688—1.6%
——0——CVE-2023-23435—1.6%
——0——CVE-2021-23243—1.6%
——0——CVE-2026-45613—1.6%
——0——CVE-2023-32864—1.6%
——0——CVE-2026-139553.3 LOW1.6%
——0Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Medium)20dCVE-2026-42443—1.6%
——0——CVE-2023-32861—1.6%
——0——CVE-2026-8720—1.6%
——0——CVE-2023-43541—1.6%
——0——CVE-2021-1038—1.6%
——0——CVE-2021-1013—1.6%
——0——CVE-2026-16926.1 MED1.6%
——0A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lure a successfully authenticated user to a malicious website.
This vulnerability only affects the following two endpoints: GraphicalData/js/signalR/connect and GraphicalData/js/signalR/reconnect.12dCVE-2026-217706.5 MED1.6%
——0HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.4dCVE-2021-1009—1.6%
——0——CVE-2023-43531—1.6%
——0——CVE-2023-28537—1.6%
——0——CVE-2025-46368—1.6%
——0——CVE-2023-43549—1.6%
——0——CVE-2023-32862—1.6%
——0——CVE-2025-61713—1.6%
——0——CVE-2023-43546—1.6%
——0——CVE-2022-20185—1.6%
——0——CVE-2021-1016—1.6%
——0——CVE-2023-32867—1.6%
——0——CVE-2020-9222—1.6%
——0——CVE-2026-622115.0 MED1.6%
——0OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.2dCVE-2026-21053—1.6%
——0——CVE-2026-12249—1.6%
——0——CVE-2023-32866—1.6%
——0——CVE-2026-33847—1.6%
——0——CVE-2025-38643—1.6%
——0——CVE-2026-12780—1.6%
——0——