Vulnerabilities exploitable today
378,755in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,413
- High8,699
- Medium6,979
- Low789
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-32681—33.9%
——10——CVE-2018-8896—33.9%
——10——CVE-2025-4643—33.9%
——10——CVE-2026-137583.7 LOW33.9%
——10CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path.
The decrypt_done($tag) form compares it against the computed tag with memNE (memcmp() != 0), which short-circuits on the first differing byte, so its run time depends on the number of matching leading bytes. This affects all five AEAD modes: GCM, CCM, ChaCha20Poly1305, EAX and OCB. The one-shot *_decrypt_verify helpers are unaffected; they verify the tag inside libtomcrypt with a constant-time comparison.
The timing difference is a tag-verification oracle. An attacker who can submit many candidate tags for the same nonce, ciphertext and associated data while measuring the timing precisely enough may recover the expected tag byte by byte and forge a message that verifies.85dCVE-2018-6772—33.9%
——10——CVE-2025-30657—33.9%
——10——CVE-2018-5079—33.9%
——10——CVE-2021-24703—33.9%
——10——CVE-2018-5082—33.9%
——10——CVE-2023-47180—33.9%
——10——CVE-2018-5085—33.9%
——10——CVE-2018-6628—33.9%
——10——CVE-2018-8996—33.9%
——10——CVE-2020-4826—33.9%
——10——CVE-2018-6627—33.9%
——10——CVE-2025-2582—33.9%
——10——CVE-2025-8156—33.9%
——10——CVE-2026-55149—33.9%
——10——CVE-2018-6771—33.9%
——10——CVE-2019-25413—33.9%
——10——CVE-2017-9724—33.9%
——10——CVE-2013-4588—33.9%
——10——CVE-2023-22088—33.9%
——10——CVE-2026-800978.6 HIG33.9%
——10Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.7dCVE-2026-2446—33.9%
——10——CVE-2012-5476—33.9%
——10——CVE-2026-40195—33.9%
——10——CVE-2020-26570—33.9%
——10——CVE-2026-581548.9 HIG33.9%
——10Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.51dCVE-2024-47944—33.9%
——10——CVE-2025-69228—33.9%
——10——CVE-2024-47362—33.9%
——10——CVE-2000-0455—33.9%
——10——CVE-2023-22932—33.9%
——10——CVE-1999-0956—33.9%
——10——CVE-1999-0807—33.9%
——10——CVE-2025-8353—33.9%
——10——CVE-2023-30476—33.9%
——10——CVE-2026-33680—33.9%
——10——CVE-2022-38093—33.9%
——10——