Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-33991—33.1%
——10——CVE-2025-32186—33.1%
——10——CVE-2021-47844—33.1%
——10——CVE-2024-11459—33.1%
——10——CVE-2024-27934—33.1%
——10——CVE-2025-32188—33.1%
——10——CVE-2025-32170—33.1%
——10——CVE-2024-21114—33.1%
——10——CVE-2016-8472—33.1%
——10——CVE-2021-45516—33.1%
——10——CVE-2022-40295—33.1%
——10——CVE-2026-174705.3 MED33.1%
——10IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.13dCVE-2022-43480—33.1%
——10——CVE-2025-32175—33.1%
——10——CVE-2008-3929—33.1%
——10——CVE-2008-4554—33.1%
——10——CVE-2026-664539.8 CRI33.1%
——10Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.39dCVE-2018-5497—33.1%
——10——CVE-2025-32190—33.1%
——10——CVE-2026-31223—33.1%
——10——CVE-2003-0440—33.1%
——10——CVE-2004-0881—33.1%
——10——CVE-2025-32192—33.1%
——10——CVE-2023-29424—33.1%
——10——CVE-2026-44895—33.1%
——10GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin: * on every response. The structural defect is that the SSE server stands up a stateful, mutation-capable RPC endpoint that is backed by the operator's GITLAB_PERSONAL_ACCESS_TOKEN without any inbound credential check, then advertises itself to every cross-origin browser context via the wildcard CORS header. The httpServer.listen(port) call at line 97 also passes no host argument, so the bind defaults to 0.0.0.0 and exposes the auth-less surface on every interface. This vulnerability is fixed in 0.6.0.61dCVE-2025-32169—33.1%
——10——CVE-2009-0149—33.1%
——10——CVE-2023-32275—33.1%
——10——CVE-2000-1137—33.1%
——10——CVE-2023-23553—33.1%
——10——CVE-2025-12593—33.1%
——10——CVE-2024-10483—33.1%
——10——CVE-2021-36189—33.1%
——10——CVE-2020-6992—33.1%
——10——CVE-2025-39572—33.1%
——10——CVE-2025-32163—33.1%
——10——CVE-2002-1875—33.1%
——10——CVE-2025-53531—33.1%
——10——CVE-2025-32189—33.1%
——10——CVE-2026-188467.5 HIG33.1%
——10IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this vulnerability to cause a denial-of-server (DoS) for that server.36d