Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,705
- Medium6,988
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-54360—34.0%
——10——CVE-2014-5509—34.0%
——10——CVE-2016-6836—34.0%
——10——CVE-2016-1420—34.0%
——10——CVE-2025-22686—34.0%
——10——CVE-2021-23227—34.0%
——10——CVE-2026-2161—34.0%
——10——CVE-2022-38195—34.0%
——10——CVE-1999-0341—34.0%
——10——CVE-1999-0340—34.0%
——10——CVE-2026-12798—34.0%
——10——CVE-2023-45715—34.0%
——10——CVE-2026-637305.0 MED34.0%
——10HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the webhook test endpoint. Attackers can bypass the insufficient hostname blacklist validation in the webhook handler to enumerate internal services, interact with internal containers, or access cloud instance metadata services including provider metadata endpoints.62dCVE-2021-29082—34.0%
——10——CVE-2016-5553—34.0%
——10——CVE-2011-5119—34.0%
——10——CVE-2004-0471—34.0%
——10——CVE-2009-3290—34.0%
——10——CVE-2015-4526—34.0%
——10——CVE-2025-10978—34.0%
——10——CVE-2020-1738—34.0%
——10——CVE-2023-40483—34.0%
——10——CVE-2004-1079—34.0%
——10——CVE-2011-5118—34.0%
——10——CVE-2024-5856—34.0%
——10——CVE-2026-130606.5 MED34.0%
——10An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios involve collections referenced within existing view pipeline definitions.49dCVE-2023-21524—34.0%
——10——CVE-2026-344308.8 HIG34.0%
——10ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based validation using shell features such as directory changes and relative paths. Attackers can exploit the incomplete shell semantics modeling to read and modify files outside the sandbox boundary and achieve arbitrary command execution through subprocess invocation with shell interpretation enabled.71dCVE-2022-40290—34.0%
——10——CVE-2003-0452—34.0%
——10——CVE-2026-7301—34.0%
——10——CVE-2024-52924—34.0%
——10——CVE-2024-49419—34.0%
——10——CVE-2026-31799—34.0%
——10——CVE-2024-4482—34.0%
——10——CVE-2024-51812—34.0%
——10——CVE-2026-94914.3 MED34.0%
——10A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.21dCVE-2018-15470—34.0%
——10——CVE-2025-10979—34.0%
——10——CVE-2024-51834—34.0%
——10——