Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,263
- High8,419
- Medium6,836
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2006-1522—35.4%
——11——CVE-2024-32675—35.4%
——11——CVE-2026-405314.3 MED35.4%
——11An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.7dCVE-2022-2259—35.4%
——11——CVE-2025-49761—35.4%
——11——CVE-2017-18710—35.4%
——11——CVE-2025-5319—35.4%
——11——CVE-2024-11521—35.4%
——11——CVE-2020-19803—35.4%
——11——CVE-2020-14735—35.4%
——11——CVE-2024-9805—35.4%
——11——CVE-2026-121618.8 HIG35.4%
——11Improper input validation in the SSH Elevate Shell feature allows an authenticated user
with permission to create or modify a shared SSH entry to execute
arbitrary commands on a remote SSH host using stored elevation
credentials via a crafted alternate username and user interaction with
the Elevate Shell action.
This affects :
- Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0
- Remote Desktop Manager 2026.1.23.0 and earlier67dCVE-2021-43034—35.4%
——11——CVE-2006-3741—35.4%
——11——CVE-2024-33631—35.4%
——11——CVE-2021-36850—35.4%
——11——CVE-2026-618426.5 MED35.4%
——11Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters to serialize that object without passing through GravSecurityPolicy::checkMethodAllowed. A user with page-author permissions can render sandboxed content that exposes plugins.* configuration secrets, including SMTP credentials, API keys, and plugin database credentials. This issue is fixed in version 2.0.2.16dCVE-2025-26596—35.4%
——11——CVE-2023-6962—35.4%
——11——CVE-2018-1000507—35.4%
——11——CVE-2022-42460—35.4%
——11——CVE-2023-4649—35.4%
——11——CVE-2024-12917—35.4%
——11——CVE-2024-27097—35.4%
——11——CVE-2024-3766—35.4%
——11——CVE-2026-737834.9 MED35.4%
——11Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.21dCVE-2024-3188—35.4%
——11——CVE-2025-3475—35.4%
——11——CVE-2025-2321—35.4%
——11——CVE-2021-36878—35.4%
——11——CVE-2022-1263—35.4%
——11——CVE-2025-47940—35.4%
——11——CVE-2024-35057—35.4%
——11——CVE-2016-2198—35.4%
——11——CVE-2004-0089—35.4%
——11——CVE-2026-3504—35.4%
——11——CVE-2025-50153—35.4%
——11——CVE-2025-53725—35.4%
——11——CVE-2025-53151—35.4%
——11——CVE-2015-2576—35.4%
——11——