Vulnerabilities exploitable today
379,275in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,375
- High8,543
- Medium7,076
- Low796
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-21039—34.8%
——10——CVE-2025-5508—34.8%
——10——CVE-2018-5846—34.8%
——10——CVE-2024-40570—34.8%
——10——CVE-2023-40554—34.8%
——10——CVE-2024-34994—34.8%
——10——CVE-2024-54245—34.8%
——10——CVE-2018-14801—34.8%
——10——CVE-2024-29153—34.8%
——10——CVE-2018-2954—34.8%
——10——CVE-2025-65358—34.8%
——10——CVE-2024-44659—34.8%
——10——CVE-2024-29726—34.8%
——10——CVE-2026-40251—34.8%
——10——CVE-2026-88057—34.8%
——10Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runtime in @angular/core and @angular/compiler could omit or select an incorrect sanitizer for security-sensitive directive host bindings because SecurityContext was derived from the declaring directive or component selector rather than the concrete host element. The mismatch is reachable through hostDirectives composition, inherited HostBinding declarations, createComponent with a custom hostElement or dynamic directives, SVG/MathML namespace elements, and tag-neutral selectors such as :not(...). Attacker-controlled href, src, action, xlink:href, or data values can therefore reach DOM attributes without Angular's built-in sanitizer and execute arbitrary JavaScript in the user's browser context. Applications unable to upgrade can use DomSanitizer.sanitize with SecurityContext.URL before assignment or restrict inputs to validated HTTP and HTTPS URL schemes. This issue is fixed in versions 20.3.28, 21.2.20, and 22.1.0.12dCVE-2024-25999—34.8%
——10——CVE-2025-21582—34.8%
——10——CVE-2024-8074—34.8%
——10——CVE-2025-57295—34.8%
——10——CVE-2024-34988—34.8%
——10——CVE-2025-29150—34.8%
——10——CVE-2026-598423.7 LOW34.8%
——10A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.2dCVE-2024-52057—34.8%
——10——CVE-2002-1500—34.8%
——10——CVE-2026-27928—34.8%
——10——CVE-2026-464655.5 MED34.8%
——10Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of externally-controlled format string vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and denial of service.78dCVE-2024-54276—34.8%
——10——CVE-2026-209237.8 HIG34.8%
——10Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.55dCVE-2025-30709—34.8%
——10——CVE-2025-57767—34.8%
——10——CVE-2023-28720—34.8%
——10——CVE-2024-29731—34.8%
——10——CVE-2026-31903—34.8%
——10——CVE-2025-71407—34.8%
——10Rejected reason: This CVE ID has been rejected as a duplicate.22dCVE-2024-6961—34.8%
——10——CVE-2025-11253—34.8%
——10——CVE-2023-51298—34.8%
——10——CVE-2006-0674—34.8%
——10——CVE-2022-47601—34.8%
——10——CVE-2026-169077.6 HIG34.8%
——10IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.38d