Vulnerabilities exploitable today
379,275in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,375
- High8,541
- Medium7,074
- Low796
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-8009—34.9%
——10——CVE-2025-7774—34.9%
——10——CVE-2016-8871—34.9%
——10——CVE-2025-24009—34.9%
——10——CVE-2016-3480—34.9%
——10——CVE-2024-13280—34.9%
——10——CVE-1999-0334—34.9%
——10——CVE-2017-0748—34.9%
——10——CVE-2018-1593—34.9%
——10——CVE-2024-8687—34.9%
——10——CVE-2026-188248.4 HIG34.9%
——10IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.20dCVE-2023-47654—34.9%
——10——CVE-2023-49160—34.9%
——10——CVE-2026-438059.8 CRI34.9%
——10A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.58dCVE-2026-626996.8 MED34.9%
——10Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.39dCVE-2026-23939—34.9%
——10——CVE-2017-4948—34.9%
——10——CVE-2022-22767—34.9%
——10——CVE-2018-19965—34.9%
——10——CVE-2018-19961—34.9%
——10——CVE-2026-4306—34.9%
——10——CVE-2024-38322—34.9%
——10——CVE-2019-25527—34.9%
——10——CVE-2024-50421—34.9%
——10——CVE-2017-18388—34.9%
——10——CVE-2024-2325—34.9%
——10——CVE-2019-2181—34.9%
——10——CVE-2026-457915.9 MED34.9%
——10Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/dokploy/server/api/routers/user.ts updates account.password without deleting other rows from session, allowing a compromised better-auth.session_token session to remain valid for up to three days after a password change. This issue is fixed in version 0.29.6.16dCVE-2012-4758—34.9%
——10——CVE-2012-3409—34.9%
——10——CVE-2026-5123—34.9%
——10——CVE-2016-6547—34.9%
——10——CVE-2023-47839—34.9%
——10——CVE-1999-0901—34.9%
——10——CVE-2026-503775.5 MED34.9%
——10Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.65dCVE-2024-30534—34.9%
——10——CVE-2025-59144—34.9%
——10debug is a JavaScript debugging utility. On 8 September 2025, the npm publishing account for debug was taken over after a phishing attack. Version 4.4.2 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a browser context (e.g. a direct <script> inclusion, or via a bundling tool such as Babel, Rollup, Vite, Next.js, etc.) there is a chance the malware still exists and such bundles will need to be rebuilt. The malware seemingly only targets cryptocurrency transactions and wallets such as MetaMask. npm removed the offending package from the registry over the course of the day on 8 September, preventing further downloads from npm proper. On 13 September, the package owner published new patch versions to help cache-bust those using private registries who might still have the compromised version cached. Users should upgrade to the latest patch version, completely remove their node_modules directory, clean their package manager's global cache, and rebuild any browser bundles from scratch. Those operating private registries or registry mirrors should purge the offending versions from any caches. This issue has been resolved in 4.4.3.18hCVE-2026-56316—34.9%
——10——CVE-2025-69036—34.9%
——10——CVE-2023-27075—34.9%
——10——