Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,372
- High8,705
- Medium6,723
- Low721
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-25051—30.0%
——9——CVE-2013-0980—30.0%
——9——CVE-2019-20551—30.0%
——9——CVE-2024-13905—30.0%
——9——CVE-2017-14271—30.0%
——9——CVE-2025-30402—30.0%
——9——CVE-2020-11874—30.0%
——9——CVE-2023-29638—30.0%
——9——CVE-2026-500839.1 CRI30.0%
——9The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, CVE-50084, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices.71dCVE-2015-6333—30.0%
——9——CVE-2023-30538—30.0%
——9——CVE-2000-1146—30.0%
——9——CVE-2003-1024—30.0%
——9——CVE-2013-2777—30.0%
——9——CVE-2012-2737—30.0%
——9——CVE-2008-1142—30.0%
——9——CVE-2002-0377—30.0%
——9——CVE-2002-0911—30.0%
——9——CVE-2001-1322—30.0%
——9——CVE-2009-2796—30.0%
——9——CVE-2005-3701—30.0%
——9——CVE-1999-1040—30.0%
——9——CVE-2007-2040—30.0%
——9——CVE-2002-0762—30.0%
——9——CVE-2007-4574—30.0%
——9——CVE-2024-0452—30.0%
——9——CVE-2026-41614—30.0%
——9——CVE-2024-55925—30.0%
——9——CVE-2026-567848.1 HIG30.0%
——9OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary alarm IDs. The removeAlarms() method in AlarmResourceImpl.java omits realm-scoping validation in its JPA query, enabling any user with alarm-write permissions to enumerate sequential auto-increment alarm IDs and delete cross-tenant alarm records without authorization.66dCVE-2026-39493—30.0%
——9——CVE-2024-25619—30.0%
——9——CVE-2023-2006—30.0%
——9——CVE-2024-24336—30.0%
——9——CVE-2026-39492—30.0%
——9——CVE-2021-45521—30.0%
——9——CVE-2026-6759—30.0%
——9——CVE-2025-503308.8 HIG30.0%
——9An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.56dCVE-2021-27194—30.0%
——9——CVE-2024-25119—30.0%
——9——CVE-2023-36380—30.0%
——9——