Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,270
- High8,461
- Medium6,876
- Low753
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-54422—35.3%
——11——CVE-2023-51335—35.3%
——11——CVE-2025-29931—35.3%
——11——CVE-2024-54358—35.3%
——11——CVE-2026-0925—35.3%
——11——CVE-2024-53696—35.3%
——11——CVE-2023-24515—35.3%
——11——CVE-2024-54305—35.3%
——11——CVE-2019-16234—35.3%
——11——CVE-2025-51869—35.3%
——11——CVE-2025-51868—35.3%
——11——CVE-2024-54312—35.3%
——11——CVE-2023-26020—35.3%
——11——CVE-2024-23889—35.3%
——11——CVE-2018-1234—35.3%
——11——CVE-2025-8467—35.3%
——11——CVE-2021-20853—35.3%
——11——CVE-2024-10934—35.3%
——11——CVE-2024-12028—35.3%
——11——CVE-2026-342097.5 HIG35.3%
——11mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative close handler validated the close voucher amount using "<" instead of "<=" against the on-chain settled amount. An attacker could submit a close voucher exactly equal to the settled amount, which would be accepted without committing any new funds, effectively closing or griefing the channel for free. This issue has been patched in version 0.4.11.63dCVE-2026-44886—35.3%
——11Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL injection. The /pialert/php/server/devices.php route accepts requests from unauthenticated users when the action URL parameter is set to getDevicesTotals. The scansource URL parameter is then injected in a SQL query. This vulnerability is fixed in 2026-05-07.67dCVE-2024-1625—35.3%
——11——CVE-2019-19620—35.3%
——11——CVE-2023-35337—35.3%
——11——CVE-2023-36568—35.3%
——11——CVE-2021-41133—35.3%
——11——CVE-2024-54274—35.3%
——11——CVE-2023-42054—35.3%
——11——CVE-2025-3649—35.3%
——11——CVE-2024-23887—35.3%
——11——CVE-2025-47912—35.3%
——11——CVE-2023-42065—35.3%
——11——CVE-2026-559556.5 MED35.3%
——11Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.77dCVE-2020-7303—35.3%
——11——CVE-2020-8338—35.3%
——11——CVE-2024-23883—35.3%
——11——CVE-2024-1529—35.3%
——11——CVE-2026-658897.5 HIG35.3%
——11Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.51dCVE-2024-54233—35.3%
——11——CVE-2025-6573—35.3%
——11——