Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-10140—32.0%
——10——CVE-2026-32034—32.0%
——10——CVE-2017-0707—32.0%
——10——CVE-2023-28532—32.0%
——10——CVE-2026-8121—32.0%
——10——CVE-2025-59011—32.0%
——10——CVE-2025-9957—32.0%
——10——CVE-2026-7704—32.0%
——10——CVE-2024-10004—32.0%
——10——CVE-2024-38769—32.0%
——10——CVE-2024-37220—32.0%
——10——CVE-2025-12913—32.0%
——10——CVE-2023-3095—32.0%
——10——CVE-2026-396237.5 HIG32.0%
——10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife allows PHP Local File Inclusion.This issue affects Biolife: from n/a through <= 3.2.3.59dCVE-2026-789776.5 MED32.0%
——10Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)25dCVE-2024-37887—32.0%
——10——CVE-2024-43270—32.0%
——10——CVE-2026-108226.5 MED32.0%
——10If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.
BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.61dCVE-2025-51511—32.0%
——10——CVE-2026-396797.5 HIG32.0%
——10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Freeio freeio allows PHP Local File Inclusion.This issue affects Freeio: from n/a through <= 1.3.21.59dCVE-2025-67924—32.0%
——10——CVE-2024-5401—32.0%
——10——CVE-2005-3345—32.0%
——10——CVE-2023-45187—32.0%
——10——CVE-2017-0351—32.0%
——10——CVE-2024-38783—32.0%
——10——CVE-2026-32364—32.0%
——10——CVE-2026-396847.5 HIG32.0%
——10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnTheme OrganicFood organicfood allows PHP Local File Inclusion.This issue affects OrganicFood: from n/a through <= 3.6.4.59dCVE-2024-34822—32.0%
——10——CVE-2015-2580—32.0%
——10——CVE-2023-48739—32.0%
——10——CVE-2023-39492—32.0%
——10——CVE-2025-25468—32.0%
——10——CVE-2024-43219—32.0%
——10——CVE-2026-33593—32.0%
——10——CVE-2024-37926—32.0%
——10——CVE-2024-37921—32.0%
——10——CVE-2024-35683—32.0%
——10——CVE-2022-2172—32.0%
——10——CVE-2023-47823—32.0%
——10——