Vulnerabilities exploitable today
377,415in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H3
Exploit Today ≥ 701,647
Distribution · last window
- Critical2,355
- High8,510
- Medium6,633
- Low715
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-478556.0 MED30.6%
——9Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.18dCVE-2020-4996—30.6%
——9——CVE-2020-9100—30.6%
——9——CVE-2024-41857—30.6%
——9——CVE-2025-39595—30.6%
——9——CVE-2026-33022—30.6%
——9——CVE-2022-3399—30.6%
——9——CVE-2025-21160—30.6%
——9——CVE-2024-48915—30.6%
——9——CVE-2025-143008.1 HIG30.6%
——9The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).35dCVE-2026-571409.4 CRI30.6%
——9PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authentication middleware. A remote caller who can reach the service can obtain agent names, roles, and instruction prefixes and can invoke a selected agent, potentially reaching its tools, memory, external APIs, credentials, and workflow state. An initial remediation was released in version 1.7.2.3dCVE-2024-56430—30.6%
——9——CVE-2025-57564—30.6%
——9——CVE-2014-6195—30.6%
——9——CVE-2012-3317—30.6%
——9——CVE-2000-1208—30.6%
——9——CVE-2026-54659—30.6%
——9Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6.50dCVE-2025-39471—30.6%
——9——CVE-2023-1003—30.6%
——9——CVE-2010-4706—30.6%
——9——CVE-2024-37930—30.6%
——9——CVE-2023-32980—30.6%
——9——CVE-2025-10710—30.6%
——9——CVE-2018-7687—30.6%
——9——CVE-2022-42844—30.6%
——9——CVE-2023-33534—30.6%
——9——CVE-2021-1751—30.6%
——9——CVE-2025-0693—30.6%
——9——CVE-2025-41367—30.6%
——9——CVE-2025-22620—30.6%
——9——CVE-2024-45981—30.6%
——9——CVE-2019-10343—30.6%
——9——CVE-2014-5206—30.6%
——9——CVE-2026-436636.5 MED30.6%
——9The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.32dCVE-2025-1364—30.6%
——9——CVE-2024-12271—30.6%
——9——CVE-2024-9417—30.6%
——9——CVE-2026-637568.1 HIG30.6%
——9SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate authenticated traffic is active to execute operations with hijacked user privileges.58dCVE-2022-43528—30.6%
——9——CVE-2023-35936—30.6%
——9——