Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,385
- High10,082
- Medium5,024
- Low463
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-688257.5 HIG—
——0HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.17hCVE-2026-217527.5 HIG—
——0HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.17hCVE-2026-61839——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61451. Reason: This candidate is a duplicate of CVE-2026-61451. Notes: All CVE users should reference CVE-2026-61451 instead of this candidate.41dCVE-2026-12555——
——0Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.10hCVE-2020-37265——
——0Rejected reason: This CVE ID has been rejected.14dCVE-2026-78416——
——0Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user.10hCVE-2026-18862——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.6dCVE-2026-23690——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.15dCVE-2026-71832——
——0Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service19hCVE-2026-66737——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.27dCVE-2025-26237——
——0D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands.19hCVE-2026-16249——
——0Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage Rentals WordPress plugin. All CVE users should reference CVE-2026-15303 instead of this ID.1dCVE-2026-19561——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.6dCVE-2026-61829——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61452. Reason: This candidate is a duplicate of CVE-2026-61452. Notes: All CVE users should reference CVE-2026-61452 instead of this candidate.41dCVE-2026-18502——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.6dCVE-2026-11950——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.55dCVE-2026-273646.5 MED—
——0Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.16hCVE-2021-47990——
——0Rejected reason: This CVE ID has been rejected.14dCVE-2026-782597.3 HIG—
——0Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.16hCVE-2026-76831——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21hCVE-2021-47989——
——0Rejected reason: This CVE ID has been rejected.14dCVE-2026-76829——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21hCVE-2026-51301——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.25dCVE-2026-76830——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21hCVE-2026-51257——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.25dCVE-2026-28551—0.0%
——0——CVE-2026-9611——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.25dCVE-2026-10772——
——0Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigned to a vulnerability already covered by CVE-2026-2411, which was assigned earlier for the same defect: the Bluetooth GATT notify/indicate paths check the permissions of the Characteristic Declaration attribute rather than the Characteristic Value attribute, so the encryption/authentication requirements configured on the value are not enforced. Both identifiers describe the same root cause in subsys/bluetooth/host/gatt.c, fixed by the same commit (c3386f92fe81bd10dc23e6a115e6a80a7d863546). Use CVE-2026-2411 instead.24dCVE-2026-195687.8 HIG—
——0A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.17hCVE-2026-61606——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61457. Reason: This candidate is a duplicate of CVE-2026-61457. Notes: All CVE users should reference CVE-2026-61457 instead of this candidate.41dCVE-2020-37263——
——0Rejected reason: This CVE ID has been rejected.14dCVE-2021-47988——
——0Rejected reason: This CVE ID has been rejected.14dCVE-2026-281677.5 HIG—
——0Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.22hCVE-2026-281718.6 HIG—
——0Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.22hCVE-2026-62287——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61873. Reason: This candidate is a duplicate of CVE-2026-61873. Notes: All CVE users should reference CVE-2026-61873 instead of this candidate.41dCVE-2026-324718.5 HIG—
——0Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.22hCVE-2026-14278——
——0Rejected reason: After further coordination, CVE was determined to not be warranted.47dCVE-2026-62164——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60087. Reason: This candidate is a duplicate of CVE-2026-60087. Notes: All CVE users should reference CVE-2026-60087 instead of this candidate.41dCVE-2026-719324.9 MED—
——0Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal sequences to access arbitrary files on the device. Exploitation requires valid administrative credentials for the device's web management interface.19hCVE-2026-167426.7 MED0.0%
——0systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user15d