Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-38027—33.1%
——10——CVE-2023-25958—33.1%
——10——CVE-2023-23998—33.1%
——10——CVE-2023-26529—33.1%
——10——CVE-2022-39160—33.1%
——10——CVE-2023-25974—33.1%
——10——CVE-2023-23734—33.1%
——10——CVE-2023-40632—33.1%
——10——CVE-2025-59103—33.1%
——10——CVE-2023-25972—33.1%
——10——CVE-2024-27729—33.1%
——10——CVE-2023-23870—33.1%
——10——CVE-2023-23995—33.1%
——10——CVE-2023-24001—33.1%
——10——CVE-2023-25793—33.1%
——10——CVE-2026-393567.5 HIG33.1%
——10Drizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific escapeName() implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was wrapped in quotes or backticks. As a result, applications that pass attacker-controlled input to APIs that construct SQL identifiers or aliases, such as sql.identifier(), .as(), may allow an attacker to terminate the quoted identifier and inject SQL. This vulnerability is fixed in 0.45.2 and 1.0.0-beta.20.64dCVE-2023-24387—33.1%
——10——CVE-2022-44594—33.1%
——10——CVE-2026-3744—33.1%
——10——CVE-2022-47596—33.1%
——10——CVE-2022-47170—33.1%
——10——CVE-2024-10605—33.1%
——10——CVE-2026-560018.5 HIG33.1%
——10A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont75dCVE-2023-25978—33.1%
——10——CVE-2023-24383—33.1%
——10——CVE-2024-45408—33.1%
——10——CVE-2014-8476—33.1%
——10——CVE-2025-14641—33.1%
——10——CVE-2023-33213—33.1%
——10——CVE-2022-37402—33.1%
——10——CVE-2023-24381—33.1%
——10——CVE-2025-26620—33.1%
——10——CVE-2024-38892—33.1%
——10——CVE-2023-23675—33.1%
——10——CVE-2019-1654—33.1%
——10——CVE-2024-10548—33.1%
——10——CVE-2025-62417—33.1%
——10——CVE-2026-782528.2 HIG33.1%
——10GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of user-controlled data in the Markdown JSON table renderer.6dCVE-2011-2521—33.1%
——10——CVE-2025-6983—33.1%
——10——