Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,591
- Medium7,039
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-64373—34.5%
——10——CVE-2023-36509—34.5%
——10——CVE-2026-150899.1 CRI34.5%
——10Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.29dCVE-2025-59268—34.5%
——10——CVE-2015-7837—34.5%
——10——CVE-2014-7271—34.5%
——10——CVE-2025-64205—34.5%
——10——CVE-2024-6522—34.5%
——10——CVE-2025-57768—34.5%
——10——CVE-2025-9296—34.5%
——10——CVE-2020-3457—34.5%
——10——CVE-2024-47570—34.5%
——10——CVE-2025-14126—34.5%
——10——CVE-2024-2280—34.5%
——10——CVE-2026-46930—34.5%
——10——CVE-2022-41583—34.5%
——10——CVE-2014-8271—34.5%
——10——CVE-2024-1348—34.5%
——10——CVE-2022-20122—34.5%
——10——CVE-2006-3979—34.5%
——10——CVE-2024-1589—34.5%
——10——CVE-2010-3477—34.5%
——10——CVE-2020-1736—34.5%
——10——CVE-2009-2768—34.5%
——10——CVE-2001-0728—34.5%
——10——CVE-2025-26598—34.5%
——10——CVE-2024-13256—34.5%
——10——CVE-2015-7509—34.5%
——10——CVE-2026-14627.8 HIG34.5%
——10A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.71dCVE-2023-6384—34.5%
——10——CVE-2024-1357—34.5%
——10——CVE-2024-31308—34.5%
——10——CVE-2024-41551—34.5%
——10——CVE-2021-43767—34.5%
——10——CVE-2024-40597—34.5%
——10——CVE-2010-3310—34.5%
——10——CVE-2019-256748.2 HIG34.5%
——10CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php with malicious 'post' values to extract sensitive database information or perform time-based blind SQL injection attacks.61dCVE-2025-14751—34.5%
——10——CVE-2023-37867—34.5%
——10——CVE-2005-1831—34.5%
——10——