Vulnerabilities exploitable today
377,882in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,336
- High8,527
- Medium6,725
- Low744
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-13620—30.9%
——9——CVE-2026-437096.5 MED30.9%
——9A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.54dCVE-2023-52183—30.9%
——9——CVE-2014-3800—30.9%
——9——CVE-2025-63457—30.9%
——9——CVE-2024-10836—30.9%
——9——CVE-2025-6319—30.9%
——9——CVE-2021-3640—30.9%
——9——CVE-2025-2117—30.9%
——9——CVE-2026-198973.7 LOW30.9%
——9A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive authentication attempts. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.30dCVE-2025-6309—30.9%
——9——CVE-2026-789764.3 MED30.9%
——9Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)22dCVE-2015-4178—30.9%
——9——CVE-2009-4901—30.9%
——9——CVE-2025-10060—30.9%
——9——CVE-2009-2795—30.9%
——9——CVE-2017-17052—30.9%
——9——CVE-2023-38002—30.9%
——9——CVE-2025-6321—30.9%
——9——CVE-2024-5968—30.9%
——9——CVE-2026-38207.2 HIG30.9%
——9There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.
An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP service configuration. This may cause the underlying system to execute unintended commands during process invocation.
Potential impact includes denial-of-service attacks, arbitrary code execution, or permanent compromise of the controller.59dCVE-2025-12984—30.9%
——9——CVE-2022-41141—30.9%
——9——CVE-2021-23877—30.9%
——9——CVE-2016-1851—30.9%
——9——CVE-2023-27704—30.9%
——9——CVE-2026-120057.2 HIG30.9%
——9IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request.33dCVE-2026-367784.9 MED30.9%
——9Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the username parameter of the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.59dCVE-2016-10906—30.9%
——9——CVE-2025-39533—30.9%
——9——CVE-2024-47092—30.9%
——9——CVE-2005-1129—30.9%
——9——CVE-2011-5321—30.9%
——9——CVE-2006-7240—30.9%
——9——CVE-2023-38043—30.9%
——9——CVE-2025-26959—30.9%
——9——CVE-2023-5610—30.9%
——9——CVE-2023-32668—30.9%
——9——CVE-2013-3230—30.9%
——9——CVE-2014-5447—30.9%
——9——