Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,731
- Medium6,772
- Low724
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-64091—30.0%
——9——CVE-2023-40261—30.0%
——9——CVE-2013-1918—30.0%
——9——CVE-2008-5147—30.0%
——9——CVE-2010-3316—30.0%
——9——CVE-2023-40452—30.0%
——9——CVE-2025-49142—30.0%
——9——CVE-2011-4325—30.0%
——9——CVE-2025-23585—29.9%
——9——CVE-2026-545269.9 CRI30.0%
——9Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go ValidateUserOverrides and SanitizeUserWorkflowSpec walk only the top-level fields of WorkflowSpec via reflection, and WorkflowSpec.ArtifactGC is allow-listed wholesale; the struct behind that field, WorkflowLevelArtifactGC, has a PodSpecPatch sub-field whose contents flow unmodified into util.ApplyPodSpecPatch on the artifact-GC pod, the same sink the original fix closed for WorkflowSpec.PodSpecPatch, so a user submitting a Workflow under templateReferencing: Strict or Secure (against a referenced WorkflowTemplate that declares an output artifact and setting spec.artifactGC.strategy: OnWorkflowCompletion) can still inject an arbitrary strategic merge patch into the artifact-GC pod, including hostPath volumes, privileged: true, arbitrary image and command, and hostNetwork: true, defeating the stated purpose of Strict/Secure reference mode. This issue is fixed in versions 3.7.15 and 4.0.6.50dCVE-2025-61748—30.0%
——9——CVE-2024-53828—30.0%
——9——CVE-2018-7305—30.0%
——9——CVE-2026-122949.6 CRI30.0%
——9Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.65dCVE-2010-5220—30.0%
——9——CVE-2016-8031—30.0%
——9——CVE-2023-27325—30.0%
——9——CVE-2025-31872—30.0%
——9——CVE-2008-5034—30.0%
——9——CVE-2024-4866—30.0%
——9——CVE-2012-0216—30.0%
——9——CVE-2025-23520—29.9%
——9——CVE-2026-44440—30.0%
——9——CVE-2024-45057—30.0%
——9——CVE-2025-23576—30.0%
——9——CVE-2026-781355.6 MED30.0%
——9libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.2dCVE-2024-39328—30.0%
——9——CVE-2025-31794—30.0%
——9——CVE-2024-39777—30.0%
——9——CVE-2023-47640—30.0%
——9——CVE-2025-46736—30.0%
——9——CVE-2026-21851—30.0%
——9——CVE-2024-36216—30.0%
——9——CVE-2026-28459—30.0%
——9——CVE-2007-3848—30.0%
——9——CVE-2024-12701—30.0%
——9——CVE-2022-4773—30.0%
——9——CVE-2024-12422—30.0%
——9——CVE-2024-13355—30.0%
——9——CVE-2024-6107—30.0%
——9——