Vulnerabilities exploitable today
379,275in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,375
- High8,542
- Medium7,076
- Low796
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-48391—34.9%
——10——CVE-2026-41079—34.9%
——10——CVE-2025-5152—34.9%
——10——CVE-2024-4857—34.9%
——10——CVE-2023-48227—34.9%
——10——CVE-2026-675817.5 HIG34.9%
——10Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer.
MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native). It binds the proof neither to the challenge being verified nor to any record of prior use, and the generic MPP.Plug dedup store keys on challenge.id, which is regenerated for every 402 response. On a static-price route, a single historical transfer matching the charge therefore satisfies an unbounded number of later charges, including transfers an attacker can read off a public block explorer.
This issue affects mpp: from 0.3.0 before 0.6.3.14dCVE-2008-2514—34.9%
——10——CVE-2025-51092—34.9%
——10——CVE-2020-36669—34.9%
——10——CVE-2021-1461—34.9%
——10——CVE-2003-0670—34.9%
——10——CVE-2022-1226—34.9%
——10——CVE-2023-24064—34.9%
——10——CVE-2023-27414—34.9%
——10——CVE-2006-5755—34.9%
——10——CVE-2023-21992—34.9%
——10——CVE-2018-5995—34.9%
——10——CVE-2022-39183—34.9%
——10——CVE-2026-59160—34.9%
——10——CVE-2025-40712—34.9%
——10——CVE-2010-3297—34.9%
——10——CVE-2025-3304—34.9%
——10——CVE-2026-792928.3 HIG34.9%
——10Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)28dCVE-2024-56139—34.9%
——10——CVE-2022-2617—34.9%
——10——CVE-2023-24062—34.9%
——10——CVE-2026-729209.8 CRI34.9%
——10SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.15dCVE-2021-22511—34.9%
——10——CVE-2025-31066—34.9%
——10——CVE-2024-34821—34.9%
——10——CVE-2022-45837—34.9%
——10——CVE-2026-694906.8 MED34.9%
——10Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.8dCVE-2026-695666.8 MED34.9%
——10Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.10dCVE-2015-0136—34.9%
——10——CVE-2024-4616—34.9%
——10——CVE-2009-5100—34.9%
——10——CVE-2019-19043—34.9%
——10——CVE-2006-4172—34.9%
——10——CVE-2019-14410—34.9%
——10——CVE-2023-21921—34.9%
——10——