Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2008-4948—32.9%
——10——CVE-2008-4965—32.9%
——10——CVE-2026-257825.3 MED32.9%
——10Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.77dCVE-2024-10197—32.9%
——10——CVE-2008-4971—32.9%
——10——CVE-2020-29482—32.9%
——10——CVE-2026-108838.8 HIG32.9%
——10Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)62dCVE-2023-40969—32.9%
——10——CVE-2021-4404—32.9%
——10——CVE-2026-781864.3 MED32.9%
——10A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation of the argument User-Name causes reachable assertion. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c9abe09421eb99bbf1cd7862a3d375e58a4eb9e4. It is recommended to apply a patch to fix this issue.29dCVE-2008-4941—32.9%
——10——CVE-2009-0168—32.9%
——10——CVE-2026-8994—32.9%
——10——CVE-2022-42944—32.9%
——10——CVE-2024-4711—32.9%
——10——CVE-2022-50925—32.9%
——10——CVE-2006-1797—32.9%
——10——CVE-2023-22514—32.9%
——10——CVE-2025-26305—32.9%
——10——CVE-2025-64359—32.9%
——10——CVE-2008-4939—32.9%
——10——CVE-2020-7319—32.9%
——10——CVE-2008-4958—32.9%
——10——CVE-2022-42446—32.9%
——10——CVE-2024-6934—32.9%
——10——CVE-2025-68544—32.9%
——10——CVE-2008-4942—32.9%
——10——CVE-2020-5376—32.9%
——10——CVE-2008-4940—32.9%
——10——CVE-2025-504947.5 HIG32.9%
——10Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.79dCVE-2025-11030—32.9%
——10——CVE-2018-6239—32.9%
——10——CVE-2023-49279—32.9%
——10——CVE-2008-4981—32.9%
——10——CVE-2007-4732—32.9%
——10——CVE-2008-4975—32.9%
——10——CVE-2012-0064—32.9%
——10——CVE-2008-4960—32.9%
——10——CVE-2024-40884—32.9%
——10——CVE-2025-31123—32.9%
——10——