Vulnerabilities exploitable today
358,551in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,689
- High11,686
- Medium7,455
- Low690
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-2063—90.4%
——27——CVE-2019-7031—90.4%
——27——CVE-2015-8726—90.4%
——27——CVE-2007-6036—90.4%
——27——CVE-2019-7965—90.4%
——27——CVE-2002-0796—90.4%
——27——CVE-2019-5611—90.4%
——27——CVE-2024-36516—90.4%
——27——CVE-2009-3605—90.4%
——27——CVE-2007-2182—90.4%
——27——CVE-2003-0592—90.4%
——27——CVE-2019-7087—90.4%
——27——CVE-2016-4059—90.4%
——27——CVE-2019-19363—90.4%
——27——CVE-2020-7663—90.4%
——27——CVE-2006-1459—90.4%
——27——CVE-2024-48841—90.4%
——27——CVE-2014-4942—90.4%
——27——CVE-2022-28719—90.4%
——27——CVE-2018-0470—90.4%
——27——CVE-2017-5154—90.4%
——27——CVE-2014-0537—90.4%
——27——CVE-2021-1140—90.4%
——27——CVE-2012-0751—90.4%
——27——CVE-2007-3984—90.4%
——27——CVE-2015-8736—90.4%
——27——CVE-2018-0890—90.4%
——27——CVE-2006-4332—90.4%
——27——CVE-2026-05459.8 CRI90.4%
——27In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`) and any job function is allowlisted, any network client can submit, read, search, and cancel jobs without credentials, bypassing basic-auth entirely. This can lead to unauthenticated remote code execution if allowed jobs perform privileged actions such as shell execution or filesystem changes. Even if jobs are deemed safe, this still constitutes an authentication bypass, potentially resulting in job spam, denial of service (DoS), or data exposure in job results.22dCVE-2023-347529.8 CRI90.4%
——27bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.34dCVE-2007-6110—90.4%
——27——CVE-2020-10859—90.4%
——27——CVE-2022-21883—90.4%
——27——CVE-2018-154548.6 HIG90.4%
——27A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of SIP traffic. An attacker could exploit this vulnerability by sending SIP requests designed to specifically trigger this issue at a high rate across an affected device. Software updates that address this vulnerability are not yet available.17hCVE-2012-4771—90.4%
——27——CVE-2001-0669—90.4%
——27——CVE-2015-3091—90.4%
——27——CVE-2014-0424—90.4%
——27——CVE-2023-23162—90.4%
——27——CVE-2017-7912—90.4%
——27——