Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2006-4342—32.9%
——10——CVE-2024-4627—32.9%
——10——CVE-2025-0869—32.9%
——10——CVE-2026-52780—32.9%
——10——CVE-2024-11683—32.9%
——10——CVE-2015-3700—32.9%
——10——CVE-2026-81030—32.9%
——10——CVE-2025-54700—32.9%
——10——CVE-2024-9938—32.9%
——10——CVE-2023-30111—32.9%
——10——CVE-2023-35061—32.9%
——10——CVE-2024-10668—32.9%
——10——CVE-2018-15371—32.9%
——10——CVE-2021-46662—32.9%
——10——CVE-2014-2608—32.9%
——10——CVE-2019-4078—32.9%
——10——CVE-2017-6951—32.9%
——10——CVE-2026-33173—32.9%
——10——CVE-2023-28801—32.9%
——10——CVE-2018-12148—32.9%
——10——CVE-2025-1085—32.9%
——10——CVE-2024-45967—32.9%
——10——CVE-2024-12260—32.9%
——10——CVE-2023-2360—32.9%
——10——CVE-2024-9966—32.9%
——10——CVE-2024-506596.1 MED32.9%
——10Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.html.79dCVE-2023-33359—32.9%
——10——CVE-2024-21517—32.9%
——10——CVE-2018-10195—32.9%
——10——CVE-2024-43120—32.9%
——10——CVE-2016-7437—32.9%
——10——CVE-2025-27679—32.9%
——10——CVE-2023-39918—32.9%
——10——CVE-2026-26700—32.9%
——10——CVE-2026-487677.6 HIG32.9%
——10TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Google Sheets helper `getAccessToken`. The vulnerable path checks only whether the caller has read access to the workspace, decrypts the stored Google OAuth credential, refreshes or retrieves the access token through the Google client, and returns the raw bearer token directly to the caller. Because guest members can also enumerate credential identifiers, a guest can mint and reuse the workspace's Google access token outside Typebot. Version 3.17.0 patches the issue.13dCVE-2026-653748.8 HIG32.9%
——10A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may result in code execution.7dCVE-2025-60219—32.9%
——10——CVE-2010-4175—32.9%
——10——CVE-2026-20098—32.9%
——10——CVE-2025-53791—32.9%
——10——