Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-34475—33.5%
——10——CVE-2025-1311—33.5%
——10——CVE-2023-43664—33.5%
——10——CVE-2026-437875.9 MED33.5%
——10A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to leak sensitive user information.5dCVE-2023-6164—33.5%
——10——CVE-2023-40472—33.5%
——10——CVE-2026-22505—33.5%
——10——CVE-2024-36999—33.5%
——10——CVE-2024-6509—33.5%
——10——CVE-2023-34273—33.5%
——10——CVE-2015-4949—33.5%
——10——CVE-2016-5601—33.5%
——10——CVE-2026-766729.9 CRI33.5%
——10A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.3dCVE-2026-128788.8 HIG33.5%
——10In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.20dCVE-2025-1105—33.5%
——10——CVE-2019-19519—33.5%
——10——CVE-2022-27574—33.5%
——10——CVE-2026-426747.5 HIG33.5%
——10Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding.
This issue affects Advanced Access Manager: from n/a through 7.1.0.63dCVE-2024-2640—33.5%
——10——CVE-2024-51188—33.5%
——10——CVE-2024-51190—33.5%
——10——CVE-2026-51275—33.5%
——10Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.53dCVE-2025-62728—33.5%
——10——CVE-2024-33102—33.5%
——10——CVE-2026-2654—33.5%
——10——CVE-2023-25027—33.5%
——10——CVE-2025-26010—33.5%
——10——CVE-2025-3962—33.5%
——10——CVE-2012-6030—33.5%
——10——CVE-2023-47511—33.5%
——10——CVE-2023-25023—33.5%
——10——CVE-2025-41360—33.5%
——10——CVE-2025-0701—33.5%
——10——CVE-2024-43157—33.5%
——10——CVE-2023-25028—33.5%
——10——CVE-2022-45361—33.5%
——10——CVE-2026-62997—33.5%
——10Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only=True, and user-supplied load_args are silently dropped. On PyTorch versions earlier than 2.6, a malicious pickle-backed model from an attacker-influenced shared registry, downloaded checkpoint, or partitioned external source can execute arbitrary code when a Kedro pipeline loads it. The issue affects only the opt-in kedro_datasets_experimental component and does not affect users who load only trusted files. This issue is fixed in version 9.5.0.6dCVE-2026-34026—33.5%
——10——CVE-2025-15094—33.5%
——10——CVE-2026-8031—33.5%
——10——