Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-54349—33.5%
——10——CVE-2026-86784—33.5%
——10The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any higher-privileged user, such as an administrator, who reviews the affected chart.6dCVE-2022-20184—33.5%
——10——CVE-2023-30267—33.5%
——10——CVE-2022-31454—33.5%
——10——CVE-2025-9595—33.5%
——10——CVE-2025-10606—33.5%
——10——CVE-2026-208427.0 HIG33.5%
——10Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.54dCVE-2025-40585—33.5%
——10——CVE-2023-34267—33.5%
——10——CVE-2025-29315—33.5%
——10——CVE-2009-3736—33.5%
——10——CVE-2023-41893—33.5%
——10——CVE-2018-17977—33.5%
——10——CVE-2024-6173—33.5%
——10——CVE-2025-5286—33.5%
——10——CVE-2024-38669—33.5%
——10——CVE-2023-34265—33.5%
——10——CVE-2016-1340—33.5%
——10——CVE-2023-34271—33.5%
——10——CVE-2023-34268—33.5%
——10——CVE-2017-3762—33.5%
——10——CVE-2018-12204—33.5%
——10——CVE-2026-30533—33.5%
——10——CVE-2016-5601—33.5%
——10——CVE-2026-766729.9 CRI33.5%
——10A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.3dCVE-2023-37957—33.5%
——10——CVE-2026-128788.8 HIG33.5%
——10In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.20dCVE-2025-34399—33.5%
——10——CVE-2026-22510—33.5%
——10——CVE-2015-4949—33.5%
——10——CVE-2024-6509—33.5%
——10——CVE-2024-36999—33.5%
——10——CVE-2023-40472—33.5%
——10——CVE-2026-437875.9 MED33.5%
——10A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to leak sensitive user information.5dCVE-2023-6164—33.5%
——10——CVE-2010-3442—33.5%
——10——CVE-2026-55495.3 MED33.5%
——10A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded cryptographic key
. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.60dCVE-2025-8190—33.5%
——10——CVE-2016-4983—33.5%
——10——