Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-41185—33.1%
——10——CVE-2024-51554—33.1%
——10——CVE-2025-57318—33.1%
——10——CVE-2024-45172—33.1%
——10——CVE-2020-36860—33.1%
——10——CVE-2016-5615—33.1%
——10——CVE-2024-7727—33.1%
——10——CVE-2020-12768—33.1%
——10——CVE-2026-579805.4 MED33.1%
——10Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.63dCVE-2025-27893—33.1%
——10——CVE-2026-278567.4 HIG33.1%
——10Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.70dCVE-2024-9209—33.1%
——10——CVE-2025-9514—33.1%
——10——CVE-2026-21936—33.1%
——10——CVE-2024-54441—33.1%
——10——CVE-2025-49379—33.1%
——10——CVE-2026-1612—33.1%
——10——CVE-2025-57215—33.1%
——10——CVE-2019-8455—33.1%
——10——CVE-2022-41950—33.1%
——10——CVE-2025-57327—33.1%
——10——CVE-2023-5385—33.1%
——10——CVE-2024-8668—33.1%
——10——CVE-2026-410768.1 HIG33.1%
——10RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authentication. Under certain LDAP server configurations, an attacker may be able to authenticate as any LDAP-backed RT user without supplying valid credentials. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by reviewing their LDAP server's authentication policy to ensure it rejects unauthenticated bind attempts. Upgrading RT remains the recommended fix.61dCVE-2026-452794.4 MED33.1%
——10Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config value, non-admin users can in some cases copy arbitrary files (depending on unix permissions) into their own Nextcloud directory via a path traversal. It is recommended that the Nextcloud Server is upgraded to 32.0.4, 31.0.14. It is recommended that the Nextcloud Enterprise Server is upgraded to 32.0.4, 31.0.14, 30.0.17.7, 29.0.17.12, 28.0.14.1563dCVE-2007-1677—33.1%
——10——CVE-2024-9220—33.1%
——10——CVE-2026-21937—33.1%
——10——CVE-2020-4788—33.1%
——10——CVE-2026-21941—33.1%
——10——CVE-2025-55068—33.1%
——10——CVE-2020-205864.5 MED33.1%
——10A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and password.76dCVE-2024-8793—33.1%
——10——CVE-2022-41248—33.1%
——10——CVE-2025-7886—33.1%
——10——CVE-2026-463697.5 HIG33.1%
——10Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transaction::is_valid_at, allowing a remote attacker to replay the same signed transaction during a blocks_per_batch minus one block window and cause the sender and recipient balances to be updated twice. This issue is fixed in version 1.5.1.26dCVE-2025-26278—33.1%
——10——CVE-2024-1346—33.1%
——10——CVE-2024-9228—33.1%
——10——CVE-2024-43285—33.1%
——10——