Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,590
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2015-4625—34.5%
——10——CVE-2025-60197—34.5%
——10——CVE-2020-12355—34.5%
——10——CVE-2021-43767—34.5%
——10——CVE-2023-25446—34.5%
——10——CVE-2010-3310—34.5%
——10——CVE-2020-17534—34.5%
——10——CVE-2025-11677—34.5%
——10——CVE-2025-14751—34.5%
——10——CVE-2019-256748.2 HIG34.5%
——10CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php with malicious 'post' values to extract sensitive database information or perform time-based blind SQL injection attacks.61dCVE-2024-40597—34.5%
——10——CVE-2006-3979—34.5%
——10——CVE-2024-1589—34.5%
——10——CVE-2024-6522—34.5%
——10——CVE-2025-64205—34.5%
——10——CVE-2015-7837—34.5%
——10——CVE-2010-3477—34.5%
——10——CVE-2020-1736—34.5%
——10——CVE-2009-2768—34.5%
——10——CVE-2025-14126—34.5%
——10——CVE-2024-47570—34.5%
——10——CVE-2014-8271—34.5%
——10——CVE-2005-1831—34.5%
——10——CVE-2023-49993—34.5%
——10——CVE-2007-3108—34.5%
——10——CVE-2015-7509—34.5%
——10——CVE-2024-13256—34.5%
——10——CVE-2001-0728—34.5%
——10——CVE-2025-2638—34.5%
——10——CVE-2023-37867—34.5%
——10——CVE-2026-239605.4 MED34.5%
——10Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbitrary JavaScript in another user’s browser under the Argo Server origin, enabling API actions with the victim’s privileges. Versions 3.6.17 and 3.7.8 fix the issue.71dCVE-2024-2925—34.5%
——10——CVE-2024-2280—34.5%
——10——CVE-2022-41583—34.5%
——10——CVE-2026-46930—34.5%
——10——CVE-2025-26598—34.5%
——10——CVE-2026-14627.8 HIG34.5%
——10A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.71dCVE-2023-4858—34.5%
——10——CVE-2025-65713—34.5%
——10——CVE-2021-39815—34.5%
——10——