Vulnerabilities exploitable today
378,916in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,406
- High8,691
- Medium7,021
- Low797
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-57436—34.3%
——10——CVE-2022-30643—34.3%
——10——CVE-2025-65276—34.3%
——10——CVE-2023-43998—34.3%
——10——CVE-2023-30960—34.3%
——10——CVE-2024-27151—34.3%
——10——CVE-2026-54269—34.3%
——10——CVE-2026-54270—34.3%
——10——CVE-2021-1601—34.3%
——10——CVE-2026-2787—34.3%
——10——CVE-2024-25107—34.3%
——10——CVE-2023-6941—34.3%
——10——CVE-2021-1352—34.3%
——10——CVE-2022-30645—34.3%
——10——CVE-2024-235655.3 MED34.3%
——10HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.68dCVE-2025-2883—34.3%
——10——CVE-2021-1600—34.3%
——10——CVE-2026-535965.3 MED34.3%
——10FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with upload requests, leading to database overload and potential denial of service for all users. Version 1.8.224 contains a fix.64dCVE-2022-44756—34.3%
——10——CVE-2024-55946—34.3%
——10——CVE-2024-36230—34.3%
——10——CVE-2020-5180—34.3%
——10——CVE-2025-51567—34.3%
——10——CVE-2022-28836—34.3%
——10——CVE-2025-12222—34.3%
——10——CVE-2026-355425.3 MED34.3%
——10An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.61dCVE-2023-5181—34.3%
——10——CVE-2026-1061—34.3%
——10——CVE-2012-1989—34.3%
——10——CVE-2024-235685.3 MED34.3%
——10HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.68dCVE-2024-22266—34.3%
——10——CVE-2021-28644—34.3%
——10——CVE-2022-30637—34.3%
——10——CVE-2026-197493.7 LOW34.3%
——10A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.37dCVE-2025-3995—34.3%
——10——CVE-2017-5387—34.3%
——10——CVE-2012-6546—34.3%
——10——CVE-2026-3676—34.3%
——10——CVE-2024-7027—34.3%
——10——CVE-2024-32743—34.3%
——10——