Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,329
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-8904—32.7%
——10——CVE-2024-20392—32.7%
——10——CVE-2023-4457—32.7%
——10——CVE-2024-35511—32.7%
——10——CVE-2018-6632—32.7%
——10——CVE-2018-5084—32.7%
——10——CVE-2018-8989—32.7%
——10——CVE-2026-3462—32.7%
——10——CVE-2025-13281—32.7%
——10——CVE-2018-6769—32.7%
——10——CVE-2026-54329—32.7%
——10——CVE-2020-2905—32.7%
——10——CVE-2021-34714—32.7%
——10——CVE-2018-6779—32.7%
——10——CVE-2018-9054—32.7%
——10——CVE-2026-598056.5 MED32.7%
——10Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by sending PUT requests to the revoke_access and undo_revoke_access actions without seller ownership validation. Attackers can modify the is_access_revoked status on arbitrary purchases to unauthorized revoke or restore buyer access to products they do not own.74dCVE-2018-8875—32.7%
——10——CVE-2018-6629—32.7%
——10——CVE-2018-6626—32.7%
——10——CVE-2018-9004—32.7%
——10——CVE-2018-9002—32.7%
——10——CVE-2018-6771—32.7%
——10——CVE-2018-8765—32.7%
——10——CVE-2014-4498—32.7%
——10——CVE-2018-9007—32.7%
——10——CVE-2018-9042—32.7%
——10——CVE-2025-6262—32.7%
——10——CVE-2018-8998—32.7%
——10——CVE-2018-5219—32.7%
——10——CVE-2018-5085—32.7%
——10——CVE-2022-29820—32.7%
——10——CVE-2018-9000—32.7%
——10——CVE-2018-6785—32.7%
——10——CVE-2018-6786—32.7%
——10——CVE-2022-28541—32.7%
——10——CVE-2018-6627—32.7%
——10——CVE-2018-5218—32.7%
——10——CVE-2018-9041—32.7%
——10——CVE-2018-8996—32.7%
——10——CVE-2018-9050—32.7%
——10——