Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,266
- High8,430
- Medium6,848
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-11036—35.4%
——11——CVE-2024-49084—35.4%
——11——CVE-2026-3504—35.4%
——11——CVE-2016-2198—35.4%
——11——CVE-2004-0089—35.4%
——11——CVE-2017-17807—35.4%
——11——CVE-2020-25184—35.4%
——11——CVE-2023-47697—35.4%
——11——CVE-2020-275187.8 HIG35.4%
——11All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could leverage several openvpn options to execute code as root/SYSTEM.79dCVE-2024-56008—35.4%
——11——CVE-2023-47764—35.4%
——11——CVE-2026-126949.1 CRI35.4%
——11Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.70dCVE-2023-34100—35.4%
——11——CVE-2026-23845—35.4%
——11——CVE-2015-0403—35.4%
——11——CVE-2024-31368—35.4%
——11——CVE-2005-1762—35.4%
——11——CVE-2026-20882—35.4%
——11——CVE-2017-13200—35.4%
——11——CVE-2019-17262—35.4%
——11——CVE-2018-12153—35.4%
——11——CVE-2019-17261—35.4%
——11——CVE-2024-43209—35.4%
——11——CVE-2025-2384—35.4%
——11——CVE-2026-141917.8 HIG35.4%
——11An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.79dCVE-2026-3488—35.4%
——11——CVE-2005-3012—35.4%
——11——CVE-2026-598067.4 HIG35.4%
——11Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file= endpoint. Attackers can craft a malicious FileData response targeting internal endpoints such as cloud metadata services to retrieve sensitive credentials including EC2 IAM role credentials.77dCVE-2026-5029—35.4%
——11——CVE-2023-45028—35.4%
——11——CVE-2025-68920—35.4%
——11——CVE-2023-41274—35.4%
——11——CVE-2024-45086—35.4%
——11——CVE-2023-42270—35.4%
——11——CVE-2021-36151—35.4%
——11——CVE-2023-47695—35.4%
——11——CVE-1999-0163—35.4%
——11——CVE-2024-20390—35.4%
——11——CVE-2025-62600—35.4%
——11——CVE-2026-502259.1 CRI35.4%
——11The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.65d