Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,263
- High8,418
- Medium6,834
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-67488—35.5%
——11——CVE-2024-6557—35.5%
——11——CVE-2025-44904—35.5%
——11——CVE-2020-3173—35.5%
——11——CVE-2026-4712—35.5%
——11——CVE-2026-749667.5 HIG35.5%
——11Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.31dCVE-2024-21685—35.5%
——11——CVE-2025-24679—35.5%
——11——CVE-2026-43387.5 HIG35.5%
——11The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts63dCVE-2026-77780—35.5%
——11Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus
Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting
creation permissions to disclose another company's bank account name, bank name and card
last four digits via a bank_account_id or bank_card_id belonging to that company in POST
/transaction/save, which is persisted and rendered without any company ownership check.24dCVE-2025-30122—35.5%
——11——CVE-2025-30098—35.5%
——11——CVE-2020-13407—35.5%
——11——CVE-2020-13408—35.5%
——11——CVE-2020-35347—35.5%
——11——CVE-2019-4038—35.5%
——11——CVE-2008-3539—35.5%
——11——CVE-2026-26938—35.5%
——11——CVE-2025-65563—35.5%
——11——CVE-2026-749547.5 HIG35.5%
——11Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.38dCVE-2026-40318—35.5%
——11——CVE-2024-5614—35.5%
——11——CVE-2026-3465—35.5%
——11——CVE-2009-1895—35.5%
——11——CVE-2024-3956—35.5%
——11——CVE-2026-199286.3 MED35.5%
——11A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.9.8-hotfix1 and 0.9.8 mitigates this issue. This patch is called 788cace0af816aa972a713a4631c57f16f895e6b. Upgrading the affected component is recommended.36dCVE-2025-69182—35.5%
——11——CVE-2024-31617—35.5%
——11——CVE-2019-20673—35.5%
——11——CVE-2024-3723—35.5%
——11——CVE-2025-69183—35.5%
——11——CVE-2022-23996—35.5%
——11——CVE-2022-23997—35.5%
——11——CVE-2024-38693—35.5%
——11——CVE-2026-30867—35.5%
——11——CVE-2025-40566—35.5%
——11——CVE-2020-11787—35.5%
——11——CVE-2016-3792—35.5%
——11——CVE-2015-4163—35.5%
——11——CVE-2026-377506.1 MED35.5%
——11A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arbitrary JavaScript in victim's browsers via the unsanitized type parameter in register.php.67d