Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,589
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-22868—34.6%
——10——CVE-2026-169586.5 MED34.6%
——10IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.30dCVE-2024-54040—34.6%
——10——CVE-2005-2766—34.6%
——10——CVE-2026-48510—34.6%
——10——CVE-2025-1568—34.6%
——10——CVE-2024-35083—34.6%
——10——CVE-2026-24158—34.6%
——10——CVE-2026-3323—34.6%
——10——CVE-2026-23776.5 MED34.6%
——10A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery (SSRF), could allow an attacker to send requests from the application's internal network, potentially leading to the disclosure of sensitive information.13dCVE-2024-36423—34.6%
——10——CVE-2026-50708—34.6%
——10——CVE-2025-25381—34.6%
——10——CVE-2026-663266.5 MED34.6%
——10Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.48dCVE-2008-4976—34.6%
——10——CVE-2005-2990—34.6%
——10——CVE-2026-9588—34.6%
——10A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content supplied by authenticated users, allowing malicious JavaScript supplied through the template_text parameter to be stored server-side and subsequently rendered to other users.68dCVE-2024-37146—34.6%
——10——CVE-2026-688388.0 HIG34.6%
——10Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.9dCVE-2017-3578—34.6%
——10——CVE-2023-30723—34.6%
——10——CVE-2025-20113—34.6%
——10——CVE-2025-8109—34.6%
——10——CVE-2026-334455.9 MED34.6%
——10CVE-2026-33445 is a memory management
vulnerability in Secure Access servers prior to 14.55. Attackers with an
intimate knowledge of and total control over the tunnel protocol can create a
persistent DoS against the server.69dCVE-2023-43292—34.6%
——10——CVE-2019-15807—34.6%
——10——CVE-2021-3729—34.5%
——10——CVE-2016-10236—34.6%
——10——CVE-2008-5300—34.6%
——10——CVE-2014-6587—34.6%
——10——CVE-2016-7383—34.6%
——10——CVE-2026-781617.3 HIG34.6%
——10A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.30dCVE-2016-7157—34.6%
——10——CVE-2026-494489.8 CRI34.6%
——10authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.63dCVE-2025-67115—34.6%
——10——CVE-2026-25775—34.6%
——10——CVE-2023-7071—34.6%
——10——CVE-2022-40203—34.6%
——10——CVE-2025-27930—34.6%
——10——CVE-2024-37300—34.6%
——10——