Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,704
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-189528.1 HIG31.7%
——10Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.31dCVE-2025-11436—31.7%
——10——CVE-2023-36126—31.7%
——10——CVE-2026-4074—31.7%
——10——CVE-2023-47072—31.7%
——10——CVE-2023-29061—31.7%
——10——CVE-2017-7346—31.7%
——10——CVE-2023-41300—31.7%
——10——CVE-2024-20917—31.6%
——10——CVE-2023-47814—31.7%
——10——CVE-2025-25035—31.7%
——10——CVE-2019-19543—31.7%
——10——CVE-2002-2384—31.7%
——10——CVE-2016-6026—31.7%
——10——CVE-1999-0190—31.7%
——10——CVE-2026-657856.5 MED31.7%
——10Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.39dCVE-2021-45335—31.7%
——10——CVE-2019-251627.8 HIG31.6%
——10In the Linux kernel, the following vulnerability has been resolved:
i2c: Fix a potential use after free
Free the adap structure only after we are done using it.
This patch just moves the put_device() down a bit to avoid the
use after free.
[wsa: added comment to the code, added Fixes tag]48dCVE-2023-5114—31.7%
——10——CVE-2025-59472—31.7%
——10——CVE-2024-20400—31.7%
——10——CVE-2025-49350—31.7%
——10——CVE-2023-52101—31.7%
——10——CVE-2025-31205—31.7%
——10——CVE-2024-423868.2 HIG31.7%
——10Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.13dCVE-2021-43284—31.7%
——10——CVE-2024-9219—31.7%
——10——CVE-2024-25435—31.7%
——10——CVE-2025-9406—31.7%
——10——CVE-2025-11047—31.7%
——10——CVE-2025-10608—31.7%
——10——CVE-2026-556686.3 MED31.7%
——10File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the user's scope. This issue is fixed in version 2.63.16.75dCVE-2006-4994—31.7%
——10——CVE-2024-11746—31.7%
——10——CVE-2024-9609—31.7%
——10——CVE-2023-2343—31.7%
——10——CVE-2023-47831—31.7%
——10——CVE-2025-82914.3 MED31.7%
——10The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the 'zipfile' module
compared to other ZIP implementations.
Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.52dCVE-2024-13591—31.7%
——10——CVE-2025-11256—31.7%
——10——