Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-23738—32.3%
——10——CVE-2026-132857.1 HIG32.3%
——10IBM MQ is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.3dCVE-2014-8823—32.3%
——10——CVE-2025-23903—32.3%
——10——CVE-2026-49444—32.3%
——10——CVE-2021-4253—32.3%
——10——CVE-2026-278442.7 LOW32.3%
——10Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service.
Version of Command Centre affected:
* 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1))
* 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3))
* 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5))
* 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7))
* all versions of 9.10 and prior.38dCVE-2025-23881—32.3%
——10——CVE-2026-132877.1 HIG32.3%
——10IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.5dCVE-2026-6456—32.3%
——10——CVE-2025-63463—32.3%
——10——CVE-2018-1448—32.3%
——10——CVE-2025-23688—32.3%
——10——CVE-2025-8219—32.3%
——10——CVE-2025-23721—32.3%
——10——CVE-2025-25161—32.3%
——10——CVE-2025-23956—32.3%
——10——CVE-2025-23668—32.3%
——10——CVE-2026-5261—32.3%
——10——CVE-2025-63466—32.3%
——10——CVE-2026-828928.1 HIG32.3%
——10IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.2dCVE-2025-26587—32.3%
——10——CVE-2026-31221—32.3%
——10——CVE-2014-0189—32.3%
——10——CVE-2019-5451—32.3%
——10——CVE-2025-25114—32.3%
——10——CVE-2025-23637—32.3%
——10——CVE-2026-5286—32.3%
——10——CVE-2024-29918—32.3%
——10——CVE-2020-37035—32.3%
——10——CVE-2025-23814—32.3%
——10——CVE-2023-40337—32.3%
——10——CVE-2021-4255—32.3%
——10——CVE-2025-23619—32.3%
——10——CVE-2025-23904—32.3%
——10——CVE-2025-25087—32.3%
——10——CVE-2024-4567—32.3%
——10——CVE-2020-2914—32.3%
——10——CVE-2025-23736—32.3%
——10——CVE-2025-26563—32.3%
——10——