Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-24618—32.4%
——10——CVE-2022-34927—32.4%
——10——CVE-2016-4831—32.4%
——10——CVE-2025-68468—32.4%
——10——CVE-2025-1199—32.4%
——10——CVE-2010-4650—32.4%
——10——CVE-2010-3381—32.4%
——10——CVE-2010-3393—32.4%
——10——CVE-2009-2282—32.4%
——10——CVE-2017-3746—32.4%
——10——CVE-2022-46089—32.4%
——10——CVE-2024-31352—32.4%
——10——CVE-2024-4612—32.4%
——10——CVE-2026-45772—32.4%
——10——CVE-2005-4175—32.4%
——10——CVE-2023-50015—32.4%
——10——CVE-2023-47772—32.4%
——10——CVE-2014-7206—32.4%
——10——CVE-2021-0009—32.4%
——10——CVE-2023-41128—32.4%
——10——CVE-2024-6367—32.4%
——10——CVE-2023-1930—32.4%
——10——CVE-2026-763178.8 HIG32.4%
——10In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could move files that the user account running Splunk Enterprise can read into a lookup that the user controls. The user could then access all relevant data and affect system integrity and availability on the search head. The vulnerability is possible because the lookup configuration endpoint does not resolve lookup source paths before checking whether they stay inside the allowed lookup staging area. For more information see About lookups (https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/10.4/use-lookups-in-splunk-web/about-lookups) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.25dCVE-2017-3756—32.4%
——10——CVE-2021-28211—32.4%
——10——CVE-2026-39899—32.4%
——10——CVE-2005-2938—32.4%
——10——CVE-2016-8214—32.4%
——10——CVE-2025-24350—32.4%
——10——CVE-2024-37002—32.4%
——10——CVE-2024-49686—32.4%
——10——CVE-2010-3353—32.4%
——10——CVE-2022-44743—32.4%
——10——CVE-2024-56144—32.4%
——10——CVE-2025-1675—32.4%
——10——CVE-2023-49180—32.4%
——10——CVE-2023-23815—32.4%
——10——CVE-2023-32957—32.4%
——10——CVE-2026-19871—32.4%
——10Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.20dCVE-2019-6331—32.4%
——10——