Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,705
- Medium6,988
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2011-5119—34.0%
——10——CVE-2021-29082—34.0%
——10——CVE-2009-3290—34.0%
——10——CVE-2016-5553—34.0%
——10——CVE-2002-2263—34.0%
——10——CVE-2026-12258—34.0%
——10Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability.5dCVE-2024-51814—34.0%
——10——CVE-2025-4075—34.0%
——10——CVE-2023-5387—34.0%
——10——CVE-2025-27217—34.0%
——10——CVE-2025-10607—34.0%
——10——CVE-2025-4780—34.0%
——10——CVE-2025-10981—34.0%
——10——CVE-2012-0860—34.0%
——10——CVE-2025-0716—34.0%
——10——CVE-2024-52974—34.0%
——10——CVE-2026-12774—34.0%
——10——CVE-2023-49079—34.0%
——10——CVE-2023-4608—34.0%
——10——CVE-2022-43706—34.0%
——10——CVE-2026-42604—34.0%
——10——CVE-2022-36263—34.0%
——10——CVE-2026-170068.3 HIG34.0%
——10IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.27dCVE-2023-41166—34.0%
——10——CVE-2021-44024—34.0%
——10——CVE-2026-1801—34.0%
——10——CVE-2025-27034—34.0%
——10——CVE-2025-21483—34.0%
——10——CVE-2026-187717.5 HIG34.0%
——10Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass.
This issue affects Talassoft Industrial Management Software: from V4 before V.16.21dCVE-2026-12772—34.0%
——10——CVE-2023-5506—34.0%
——10——CVE-2023-5415—34.0%
——10——CVE-2025-3839—34.0%
——10——CVE-2026-149488.8 HIG34.0%
——10A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.20dCVE-2024-29474—34.0%
——10——CVE-2026-40721—34.0%
——10——CVE-2021-20194—34.0%
——10——CVE-2022-1251—34.0%
——10——CVE-2007-0366—34.0%
——10——CVE-2020-5865—34.0%
——10——