Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-3101—33.0%
——10——CVE-2017-14568—33.0%
——10——CVE-2025-26308—33.0%
——10——CVE-2017-14549—33.0%
——10——CVE-2004-1058—33.0%
——10——CVE-2017-14557—33.0%
——10——CVE-2011-4086—33.0%
——10——CVE-2025-55071—33.0%
——10——CVE-2025-8533—33.0%
——10——CVE-2026-46805—33.0%
——10——CVE-2026-56268—33.0%
——10——CVE-2016-8818—33.0%
——10——CVE-2017-14571—33.0%
——10——CVE-2017-14559—33.0%
——10——CVE-2016-8819—33.0%
——10——CVE-2017-14567—33.0%
——10——CVE-2016-8814—33.0%
——10——CVE-2025-43866—33.0%
——10——CVE-2017-14298—33.0%
——10——CVE-2017-14561—33.0%
——10——CVE-2023-381767.0 HIG33.0%
——10Azure Arc-Enabled Servers Elevation of Privilege Vulnerability43dCVE-2026-23429.3 CRI33.0%
——10Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS.
This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.75dCVE-2017-10746—33.0%
——10——CVE-2017-14272—33.0%
——10——CVE-2001-0073—33.0%
——10——CVE-2017-14177—33.0%
——10——CVE-2017-14542—33.0%
——10——CVE-2026-101164.3 MED33.0%
——10A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in the library /lib/core/ogs-timer.c of the component ue-authentications Endpoint. Performing a manipulation results in denial of service. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Applying a patch is the recommended action to fix this issue.63dCVE-2017-14579—33.0%
——10——CVE-2012-0745—33.0%
——10——CVE-2017-14292—33.0%
——10——CVE-2023-7007—33.0%
——10——CVE-2017-14566—33.0%
——10——CVE-2025-26310—33.0%
——10——CVE-2026-790909.8 CRI33.0%
——10Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)25dCVE-2024-20298—33.0%
——10——CVE-2023-51550—33.0%
——10——CVE-2025-54852—33.0%
——10——CVE-2024-11337—33.0%
——10——CVE-2018-1652—33.0%
——10——