Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,263
- High8,419
- Medium6,836
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-27428—35.4%
——11——CVE-2026-48502—35.4%
——11——CVE-2022-30325—35.4%
——11——CVE-2024-9779—35.4%
——11——CVE-2026-48683—35.4%
——11——CVE-2025-560157.5 HIG35.4%
——11In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.67dCVE-2025-25264—35.4%
——11——CVE-2024-459936.5 MED35.4%
——11Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.83dCVE-2008-0266—35.4%
——11——CVE-2023-7193—35.4%
——11——CVE-2022-44726—35.4%
——11——CVE-2024-39809—35.4%
——11——CVE-2024-30529—35.4%
——11——CVE-2023-38076—35.4%
——11——CVE-2024-44192—35.4%
——11——CVE-2021-36839—35.4%
——11——CVE-2006-1528—35.4%
——11——CVE-2019-11517—35.4%
——11——CVE-2026-100658.8 HIG35.4%
——11A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.66dCVE-2026-579535.4 MED35.4%
——11Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint registered under spectator-permitted middleware. Attackers with spectator role can exploit this misconfigured access control to create and delete automation workflows, making unauthorized modifications to operation automation configuration and EventGroups.73dCVE-2024-7092—35.4%
——11——CVE-2025-26595—35.4%
——11——CVE-2024-33402—35.4%
——11——CVE-2019-12455—35.4%
——11——CVE-2022-45892—35.4%
——11——CVE-2021-31798—35.4%
——11——CVE-2023-1788—35.4%
——11——CVE-2021-36830—35.4%
——11——CVE-2018-5438—35.4%
——11——CVE-2022-26375—35.4%
——11——CVE-2024-29127—35.4%
——11——CVE-2024-9952—35.4%
——11——CVE-2020-25282—35.4%
——11——CVE-2026-755235.9 MED35.4%
——11Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not inspect query strings. When Management:Endpoints:HttpExchanges:IncludeQueryString is enabled, the HttpExchangeRequest response can disclose OAuth tokens, password-reset tokens, signed-URL signatures, API keys, and other query-string secrets from prior traffic to a caller that can reach the explicitly exposed endpoint. The Steeltoe.Management.Endpoint.Actuators.HttpExchanges DEBUG logger also records these URIs, creating a second disclosure channel for users with log access. This issue is fixed in version 4.3.0.2dCVE-2024-7902—35.4%
——11——CVE-2026-35496—35.4%
——11——CVE-2026-44996—35.4%
——11——CVE-2021-0146—35.4%
——11——CVE-2024-2606—35.4%
——11——CVE-2025-13609—35.4%
——11——