Vulnerabilities exploitable today
378,755in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,413
- High8,699
- Medium6,979
- Low789
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-40741—33.8%
——10——CVE-2025-32075—33.8%
——10——CVE-2024-7512—33.8%
——10——CVE-2023-39383—33.8%
——10——CVE-2022-41599—33.8%
——10——CVE-2026-655437.5 HIG33.8%
——10Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.41dCVE-2023-42829—33.8%
——10——CVE-2019-5011—33.8%
——10——CVE-2025-67846—33.8%
——10——CVE-2026-595287.5 HIG33.8%
——10Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.57dCVE-2023-5461—33.8%
——10——CVE-2023-3947—33.8%
——10——CVE-2009-2287—33.8%
——10——CVE-2008-3077—33.8%
——10——CVE-2026-37978—33.8%
——10——CVE-2026-33025—33.8%
——10——CVE-2025-65113—33.8%
——10——CVE-2024-34001—33.8%
——10——CVE-2026-824048.3 HIG33.8%
——10TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an own property, polluting Object.prototype for the runtime. In packages/toon/src/decode/expand.ts, the expandPaths: 'safe' path and insertPathSafe function made dotted keys such as a.__proto__.x the strongest vector, while plain nested objects, tabular rows, quoted keys, and streaming decode were also affected. The encoder also dropped own __proto__ properties and could invoke an inherited setter during normalization. Services that decode untrusted TOON could experience denial of service or, when a suitable downstream gadget is present, remote code execution. This issue is fixed in version 2.3.1.20dCVE-2022-46321—33.8%
——10——CVE-2022-48312—33.8%
——10——CVE-2015-8745—33.8%
——10——CVE-2025-70841—33.8%
——10——CVE-2000-0566—33.8%
——10——CVE-2024-0898—33.8%
——10——CVE-2017-15121—33.8%
——10——CVE-2021-25471—33.8%
——10——CVE-2026-68489—33.8%
——10Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.4dCVE-2021-46875—33.8%
——10——CVE-2017-5526—33.8%
——10——CVE-2024-13016—33.8%
——10——CVE-2022-13537.1 HIG33.8%
——10A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.48dCVE-2011-3351—33.8%
——10——CVE-2022-46328—33.8%
——10——CVE-2022-48297—33.8%
——10——CVE-2024-21249—33.8%
——10——CVE-2025-32111—33.8%
——10——CVE-2021-0113—33.8%
——10——CVE-2024-1487—33.8%
——10——CVE-2023-31145—33.8%
——10——