Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,704
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2011-5238—31.6%
——9——CVE-2026-82524.3 MED31.6%
——9A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.59dCVE-2025-3069—31.6%
——9——CVE-2020-29570—31.6%
——9——CVE-2021-37209—31.6%
——9——CVE-2023-32746—31.6%
——9——CVE-2023-50369—31.6%
——9——CVE-2023-30469—31.6%
——9——CVE-2014-5431—31.6%
——9——CVE-2002-0674—31.6%
——9——CVE-2013-3222—31.6%
——9——CVE-2023-6882—31.6%
——9——CVE-2023-49179—31.6%
——9——CVE-2026-62806.5 MED31.6%
——9Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.75dCVE-2025-13544—31.6%
——9——CVE-2008-1005—31.6%
——9——CVE-2026-151056.3 MED31.6%
——9A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request Handler. This manipulation causes out-of-bounds write. The attack requires access to the local network. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.51dCVE-2021-21912—31.6%
——9——CVE-2022-376606.5 MED31.6%
——9In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encrypting element Qi and subtracting it from the captured message M (X = M - Qi). This will result in the public ephemeral key X; the only element required to subvert the PKEX association.69dCVE-2017-1381—31.6%
——9——CVE-2023-48635—31.6%
——9——CVE-2024-46655—31.6%
——9——CVE-2020-1740—31.6%
——9——CVE-2026-2515—31.6%
——9——CVE-2025-1867—31.6%
——9——CVE-2024-10743—31.6%
——9——CVE-2026-33496—31.6%
——9——CVE-2026-22714—31.6%
——9——CVE-2023-49173—31.6%
——9——CVE-2022-35895—31.6%
——9——CVE-2024-8902—31.6%
——9——CVE-2022-36783—31.6%
——9——CVE-2026-688315.5 MED31.6%
——9Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.5dCVE-2024-25928—31.6%
——9——CVE-2019-25376—31.6%
——9——CVE-2025-59563—31.6%
——9——CVE-2023-28171—31.6%
——9——CVE-2013-3225—31.6%
——9——CVE-2023-32102—31.6%
——9——CVE-2023-48289—31.6%
——9——