Vulnerabilities exploitable today
378,026in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,410
- Medium6,691
- Low753
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-3915—31.6%
——9——CVE-2024-44552—31.6%
——9——CVE-2024-44556—31.6%
——9——CVE-2025-49198—31.6%
——9——CVE-2023-21861—31.6%
——9——CVE-2023-21892—31.6%
——9——CVE-1999-0907—31.6%
——9——CVE-2024-35498—31.6%
——9——CVE-2020-5990—31.6%
——9——CVE-2023-202646.1 MED31.6%
——9A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a user who is authenticating to a remote access VPN session. This vulnerability is due to insufficient validation of the login URL. An attacker could exploit this vulnerability by persuading a user to access a site that is under the control of the attacker, allowing the attacker to modify the login URL. A successful exploit could allow the attacker to intercept a successful SAML assertion and use that assertion to establish a remote access VPN session toward the affected device with the identity and permissions of the hijacked user, resulting in access to the protected network.41dCVE-2020-16092—31.6%
——9——CVE-2026-792478.3 HIG31.6%
——9Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)25dCVE-2005-1036—31.6%
——9——CVE-2026-21411—31.6%
——9——CVE-2016-0909—31.6%
——9——CVE-2023-39399—31.6%
——9——CVE-2025-8807—31.6%
——9——CVE-2024-10380—31.6%
——9——CVE-2022-29519—31.6%
——9——CVE-2024-44549—31.6%
——9——CVE-2025-31721—31.6%
——9——CVE-2009-3564—31.6%
——9——CVE-2023-39403—31.6%
——9——CVE-2006-1274—31.6%
——9——CVE-2016-1832—31.6%
——9——CVE-2023-21973—31.6%
——9——CVE-2020-8337—31.6%
——9——CVE-2022-48286—31.6%
——9——CVE-2023-1694—31.6%
——9——CVE-2023-1693—31.6%
——9——CVE-2026-53573—31.6%
——9GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.11dCVE-2025-11113—31.6%
——9——CVE-2025-30916—31.6%
——9——CVE-2026-790246.5 MED31.6%
——9Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)25dCVE-2024-2948—31.6%
——9——CVE-2025-1275—31.6%
——9——CVE-2023-43508—31.6%
——9——CVE-2024-6025—31.6%
——9——CVE-2025-5920—31.6%
——9——CVE-2026-0612—31.6%
——9——