Vulnerabilities exploitable today
378,026in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,410
- Medium6,689
- Low753
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-6882—31.6%
——9——CVE-2023-49179—31.6%
——9——CVE-2024-2619—31.6%
——9——CVE-2024-8913—31.6%
——9——CVE-2025-0769—31.6%
——9——CVE-2022-33035—31.6%
——9——CVE-2018-10646—31.6%
——9——CVE-2026-613907.7 HIG31.6%
——9There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.61dCVE-2020-35924—31.6%
——9——CVE-2023-35090—31.6%
——9——CVE-2007-0278—31.6%
——9——CVE-2026-27413—31.6%
——9——CVE-2007-0277—31.6%
——9——CVE-2025-13468—31.6%
——9——CVE-2024-10746—31.6%
——9——CVE-2023-48317—31.6%
——9——CVE-2025-26137—31.6%
——9——CVE-2023-22614—31.6%
——9——CVE-2025-331416.5 MED31.6%
——9IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.3dCVE-2025-54575—31.6%
——9——CVE-2023-45609—31.6%
——9——CVE-2023-48321—31.6%
——9——CVE-2026-35488—31.6%
——9——CVE-2024-10745—31.6%
——9——CVE-2025-2047—31.6%
——9——CVE-2020-10610—31.6%
——9——CVE-2023-50370—31.6%
——9——CVE-2026-841439.8 CRI31.6%
——9Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.18dCVE-2019-5668—31.6%
——9——CVE-2011-10030—31.6%
——9——CVE-2018-4183—31.6%
——9——CVE-2017-12338—31.6%
——9——CVE-2012-1931—31.6%
——9——CVE-2022-47095—31.6%
——9——CVE-2015-7549—31.6%
——9——CVE-2026-939544.3 MED31.6%
——9A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 2b66ca6df8110f6b512e030b54c16b9fbe318f17. Applying a patch is advised to resolve this issue. PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings.2dCVE-2026-52785—31.6%
——9——CVE-2007-3732—31.6%
——9——CVE-2023-32793—31.6%
——9——CVE-2013-3224—31.6%
——9——