Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,731
- Medium6,772
- Low724
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-4866—30.0%
——9——CVE-2025-31872—30.0%
——9——CVE-2024-39328—30.0%
——9——CVE-2026-36962—30.0%
——9——CVE-2024-39777—30.0%
——9——CVE-2023-44390—30.0%
——9——CVE-2026-25753—30.0%
——9——CVE-2023-47640—30.0%
——9——CVE-2026-605928.2 HIG30.0%
——9Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster as well as unauthorized update, insert or delete access to some of MySQL Cluster accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).16dCVE-2025-13089—30.0%
——9——CVE-2023-25153—30.0%
——9——CVE-2026-40127—30.0%
——9OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application.
This issue was fixed in OutSystems Lifetime version 11.28.2.395538dCVE-2022-29160—30.0%
——9——CVE-2026-26076—30.0%
——9——CVE-2024-6107—30.0%
——9——CVE-2026-34177—30.0%
——9——CVE-2026-725818.6 HIG30.0%
——9A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs. The /auth endpoint in api/main.py uses the user-supplied url POST parameter to redirect to a Home Assistant instance without validating the destination URL, enabling internal network scanning and access to internal services.21dCVE-2024-11331—30.0%
——9——CVE-2026-97705.3 MED30.0%
——9Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem
that is shared across devices. An
attacker with access to the firmware image can extract the embedded key.
Successful
exploitation may allow an unauthenticated attacker on the same network to use
this key in the web management service, compromising the confidentiality of
encrypted communications. This may enable passive decryption of traffic or
active man-in-the-middle (MITM) attacks43dCVE-2026-877767.5 HIG30.0%
——9compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote unauthenticated attacker can repeatedly open requests and disconnect early, exhausting the available memory and crashing the server. All applications using compression are affected. The issue is fixed in compression 1.8.2, and users should upgrade to 1.8.2 or later.2dCVE-2023-27325—30.0%
——9——CVE-2018-7305—30.0%
——9——CVE-2025-61748—30.0%
——9——CVE-2024-11569—30.0%
——9——CVE-2026-122949.6 CRI30.0%
——9Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.65dCVE-2024-53828—30.0%
——9——CVE-2024-13351—29.9%
——9——CVE-2025-52447—29.9%
——9——CVE-2025-23536—29.9%
——9——CVE-2023-2021—29.9%
——9——CVE-2026-24987—29.9%
——9——CVE-2024-21545—29.9%
——9——CVE-2024-1764—29.9%
——9——CVE-2023-32651—29.9%
——9——CVE-2025-45614—29.9%
——9——CVE-2023-41335—29.9%
——9——CVE-2014-1845—29.9%
——9——CVE-2025-1367—29.9%
——9——CVE-2024-8920—29.9%
——9——CVE-2026-27046—29.9%
——9——