Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-62789—31.9%
——10——CVE-2010-4078—31.9%
——10——CVE-2023-38077—31.9%
——10——CVE-2025-10418—31.9%
——10——CVE-2026-1425—31.9%
——10——CVE-2017-16535—31.9%
——10——CVE-2024-49338—31.9%
——10——CVE-2015-0693—31.9%
——10——CVE-2026-10094—31.9%
——10——CVE-2026-123558.1 HIG31.9%
——10IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution.5dCVE-2026-658328.2 HIG31.9%
——10Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so that the value following a modifier option poisons m_modifierTranslationTable, after which ServerProxy::translateKey() or ServerProxy::translateModifierMask() indexes the seven-row s_translationTable or s_masks arrays out of bounds, disclosing four bytes at an attacker-selected relative offset or crashing the connected client; an odd option count also causes an out-of-bounds OptionsList read. This issue is fixed in continuous build 1.26.0.299.12dCVE-2024-10896—31.9%
——10——CVE-2024-41674—31.9%
——10——CVE-2020-3459—31.9%
——10——CVE-2023-46632—31.9%
——10——CVE-2008-2101—31.9%
——10——CVE-2025-10106—31.9%
——10——CVE-2025-10421—31.9%
——10——CVE-2026-40352—31.9%
——10——CVE-2025-64233—31.9%
——10——CVE-2024-12609—31.9%
——10——CVE-2024-3940—31.9%
——10——CVE-2023-25585—31.9%
——10——CVE-2018-1768—31.9%
——10——CVE-2024-56830—31.9%
——10——CVE-2012-2745—31.9%
——10——CVE-2022-42394—31.9%
——10——CVE-2025-11552—31.9%
——10——CVE-2025-11514—31.9%
——10——CVE-2025-10826—31.9%
——10——CVE-2026-920055.3 MED31.9%
——10Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.4dCVE-2025-10620—31.9%
——10——CVE-2015-6296—31.9%
——10——CVE-2025-29981—31.9%
——10——CVE-2010-4074—31.9%
——10——CVE-2025-10429—31.9%
——10——CVE-2025-31510—31.9%
——10——CVE-2026-247088.2 HIG31.9%
——10An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.10dCVE-2019-16233—31.9%
——10——CVE-2026-654319.8 CRI31.9%
——10Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.56d