Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,600
- Medium7,039
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-2224—34.5%
——10——CVE-2015-5699—34.5%
——10——CVE-2013-4311—34.5%
——10——CVE-2026-503415.5 MED34.5%
——10Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.65dCVE-2024-43277—34.5%
——10——CVE-2005-0183—34.5%
——10——CVE-2024-12232—34.5%
——10——CVE-2026-586145.5 MED34.5%
——10Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.63dCVE-2021-0257—34.5%
——10——CVE-2025-150399.4 CRI34.5%
——10The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.
Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.42dCVE-2024-33539—34.5%
——10——CVE-2024-10433—34.5%
——10——CVE-2025-0942—34.5%
——10——CVE-2021-0228—34.5%
——10——CVE-2002-0202—34.5%
——10——CVE-2021-3790—34.5%
——10——CVE-2001-0069—34.5%
——10——CVE-2008-0595—34.5%
——10——CVE-2021-34181—34.5%
——10——CVE-2026-549975.5 MED34.5%
——10Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.65dCVE-2026-8096—34.5%
——10——CVE-2026-27466—34.5%
——10——CVE-2026-44316—34.5%
——10——CVE-2026-503005.5 MED34.5%
——10Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.63dCVE-2024-32338—34.5%
——10——CVE-2025-2851—34.5%
——10——CVE-2026-504555.5 MED34.5%
——10Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.63dCVE-2024-27680—34.5%
——10——CVE-2025-23993—34.5%
——10——CVE-2023-38080—34.5%
——10——CVE-2024-32733—34.5%
——10——CVE-2024-12920—34.5%
——10——CVE-2017-16645—34.5%
——10——CVE-2024-38949—34.5%
——10——CVE-2026-44319—34.5%
——10——CVE-2022-4189—34.5%
——10——CVE-2026-494586.1 MED34.5%
——10DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.64dCVE-2026-42482—34.5%
——10——CVE-2025-10164—34.5%
——10——CVE-2026-1229—34.5%
——10——