Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,329
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-30622—32.7%
——10——CVE-2026-876168.3 HIG32.7%
——10Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)12dCVE-2023-6359—32.7%
——10——CVE-2015-1591—32.7%
——10——CVE-2002-0088—32.7%
——10——CVE-2013-0799—32.7%
——10——CVE-2025-0969—32.7%
——10——CVE-2024-31230—32.7%
——10——CVE-2023-5598—32.7%
——10——CVE-2022-26269—32.7%
——10——CVE-2025-31798—32.7%
——10——CVE-2024-1289—32.7%
——10——CVE-2026-53930—32.7%
——10——CVE-2022-26868—32.7%
——10——CVE-2021-38933—32.7%
——10——CVE-2022-27860—32.7%
——10——CVE-2023-489405.4 MED32.7%
——10A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.76dCVE-2001-0124—32.7%
——10——CVE-2001-1063—32.7%
——10——CVE-2025-30883—32.7%
——10——CVE-2021-47476—32.7%
——10——CVE-2008-3830—32.7%
——10——CVE-2001-0470—32.7%
——10——CVE-2025-31843—32.7%
——10——CVE-2021-1053—32.7%
——10——CVE-2025-31781—32.7%
——10——CVE-2026-32719—32.7%
——10——CVE-1999-1096—32.7%
——10——CVE-1999-1176—32.7%
——10——CVE-2014-0615—32.7%
——10——CVE-2024-10861—32.7%
——10——CVE-2026-528707.6 HIG32.7%
——10The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.67dCVE-2022-22551—32.7%
——10——CVE-2014-3716—32.7%
——10——CVE-2005-2510—32.7%
——10——CVE-2022-24886—32.7%
——10——CVE-2023-4594—32.7%
——10——CVE-2023-5323—32.7%
——10——CVE-2026-334897.5 HIG32.7%
——10CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The longestMatch() function in plugin/transfer/transfer.go uses a lexicographic string comparison instead of an actual longest-suffix match to select the winning zone. As a result, a permissive parent-zone transfer rule can override a restrictive subzone rule depending on zone name ordering (e.g., "example.org." > "a.example.org." lexicographically). This allows an unauthorized remote client to perform AXFR/IXFR for the subzone and retrieve its full zone contents. This issue has been fixed in version 1.14.3.60dCVE-2022-21951—32.7%
——10——