Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-47762—31.4%
——9——CVE-2025-0051—31.4%
——9——CVE-2025-6842—31.4%
——9——CVE-2022-46265—31.4%
——9——CVE-2009-3108—31.4%
——9——CVE-2026-13544—31.3%
——9——CVE-2024-2231—31.3%
——9——CVE-2023-32296—31.3%
——9——CVE-2017-0491—31.3%
——9——CVE-2019-14302—31.3%
——9——CVE-2024-12651—31.3%
——9——CVE-2024-5212—31.3%
——9——CVE-2023-49175—31.3%
——9——CVE-2025-21947—31.3%
——9——CVE-2024-1810—31.3%
——9——CVE-2024-42697—31.3%
——9——CVE-2023-49747—31.3%
——9——CVE-2026-117717.5 HIG31.3%
——9OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server46dCVE-2025-31558—31.3%
——9——CVE-2023-41691—31.3%
——9——CVE-2011-2910—31.3%
——9——CVE-2024-23155—31.3%
——9——CVE-2008-4952—31.3%
——9——CVE-2008-4995—31.3%
——9——CVE-2026-13540—31.3%
——9——CVE-2023-1008—31.3%
——9——CVE-2006-5824—31.3%
——9——CVE-2002-1890—31.3%
——9——CVE-2025-1051—31.3%
——9——CVE-2023-5214—31.3%
——9——CVE-2020-12829—31.3%
——9——CVE-2008-4977—31.3%
——9——CVE-2023-34174—31.3%
——9——CVE-2026-32935—31.3%
——9——CVE-2026-263389.8 CRI31.3%
——9Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.69dCVE-2023-37997—31.3%
——9——CVE-2026-162226.3 MED31.3%
——9A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint. Performing a manipulation of the argument mkAddress results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.63dCVE-2024-10360—31.3%
——9——CVE-2025-41365—31.3%
——9——CVE-2015-5198—31.3%
——9——