Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,278
- High8,468
- Medium6,885
- Low756
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-39557—35.3%
——11——CVE-2022-45283—35.3%
——11——CVE-2026-40756—35.3%
——11——CVE-2020-21386—35.3%
——11——CVE-2024-34349—35.3%
——11——CVE-2025-2831—35.3%
——11——CVE-2021-40683—35.3%
——11——CVE-2024-8541—35.3%
——11——CVE-2026-527336.5 MED35.3%
——11ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::pop_tip removed a reverted tip block but did not remove subtree entries whose end_height belonged to that block, unlike the cleanup performed by pop_root. When the winning fork later finalized, the abandoned branch's stale subtree data could be written to RocksDB and survive node restarts. The corrupted history can cause z_getsubtreesbyindex consumers such as lightwalletd and light wallets to receive incorrect subtree roots, producing wallet synchronization failures or incorrect wallet state and requiring a full state rebuild for recovery. This issue is fixed in version 4.5.0.16dCVE-2009-4150—35.3%
——11——CVE-2023-38623—35.3%
——11——CVE-2026-40760—35.3%
——11——CVE-2022-3657—35.3%
——11——CVE-2026-27488—35.3%
——11——CVE-2026-40735—35.3%
——11——CVE-2026-39539—35.3%
——11——CVE-2026-56031—35.3%
——11——CVE-2023-0833—35.3%
——11——CVE-2026-27098—35.3%
——11——CVE-2023-21059—35.3%
——11——CVE-2026-592858.1 HIG35.3%
——11Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries.
Spring for GraphQL 2.0.0 - 2.0.423dCVE-2024-12001—35.3%
——11——CVE-2001-0416—35.3%
——11——CVE-2026-925706.5 MED35.3%
——11reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys for services like SecurityTrails, Shodan, Censys, VirusTotal, BinaryEdge and Hunter by querying the endpoint without role-based permission checks.2dCVE-2016-10797—35.3%
——11——CVE-2022-3160—35.3%
——11——CVE-2026-40752—35.3%
——11——CVE-2024-28013—35.3%
——11——CVE-2020-11623—35.3%
——11——CVE-2024-54546—35.3%
——11——CVE-2024-2401—35.3%
——11——CVE-2020-15855—35.3%
——11——CVE-2024-11514—35.3%
——11——CVE-2022-42147—35.3%
——11——CVE-2025-6926—35.3%
——11——CVE-2026-40733—35.3%
——11——CVE-2010-3362—35.3%
——11——CVE-2024-11516—35.3%
——11——CVE-2026-395558.1 HIG35.3%
——11Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection.
This issue affects Askka: from n/a through 1.3.1.65dCVE-2023-21060—35.3%
——11——