Vulnerabilities exploitable today
4,338in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,256
- High9,258
- Medium5,266
- Low507
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2009-1536—98.9%
——30——CVE-2020-35131—98.9%
——30——CVE-2010-4052—98.9%
——30——CVE-2024-26331—98.9%
——30——CVE-2020-7046—98.9%
——30——CVE-2024-265949.1 CRI98.9%
——30In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate mech token in session setup
If client send invalid mech token in session setup request, ksmbd
validate and make the error if it is invalid.27dCVE-2021-344787.8 HIG98.9%
——30Microsoft Office Remote Code Execution Vulnerability21dCVE-2020-11998—98.9%
——30——CVE-2016-2345—98.9%
——30——CVE-2009-1537—98.9%
KEV—80Microsoft DirectX NULL Byte Overwrite Vulnerability—CVE-2022-0557—98.9%
——30——CVE-2021-28635—98.9%
——30——CVE-2021-369527.8 HIG98.9%
——30Visual Studio Remote Code Execution Vulnerability21dCVE-2005-2733—98.9%
——30——CVE-2021-35598—98.9%
——30——CVE-2021-35594—98.9%
——30——CVE-2021-35593—98.9%
——30——CVE-2002-0563—98.8%
——30——CVE-2015-2502—98.8%
KEV—80Microsoft Internet Explorer Memory Corruption Vulnerability—CVE-2002-0013—98.8%
——30——CVE-2008-1365—98.8%
——30——CVE-2014-0282—98.8%
——30——CVE-2024-38030—98.8%
——30——CVE-2025-53690—98.8%
KEV—80Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability—CVE-2014-1823—98.8%
——30——CVE-2010-0033—98.8%
——30——CVE-2010-0557—98.8%
——30——CVE-2008-2431—98.8%
——30——CVE-2021-28474—98.8%
——30——CVE-2018-8823—98.8%
——30——CVE-2014-3206—98.8%
——30——CVE-2025-11833—98.8%
——30——CVE-2018-11763—98.8%
——30——CVE-2024-2862—98.8%
——30——CVE-2016-0199—98.8%
——30——CVE-2022-26960—98.8%
——30——CVE-2018-8552—98.8%
——30——CVE-2000-0869—98.8%
——30——CVE-2021-21480—98.8%
——30——CVE-2016-5388—98.8%
——30——