Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,732
- Medium6,772
- Low724
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-45304—29.9%
——9——CVE-2025-1367—29.9%
——9——CVE-2025-24002—29.9%
——9——CVE-2024-46327—29.9%
——9——CVE-2024-6019—29.9%
——9——CVE-2024-33929—29.9%
——9——CVE-2023-1689—29.9%
——9——CVE-2024-31798—29.9%
——9——CVE-2026-562497.6 HIG29.9%
——9Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authenticated users to overwrite existing channels by reusing their names. Attackers with app.create_channel permission can exploit a logic mismatch between existence validation and upsert operations to reassign channel ownership and modify critical production channel configurations.79dCVE-2025-23564—29.9%
——9——CVE-2022-34009—29.9%
——9——CVE-2005-1627—29.9%
——9——CVE-2025-31203—29.9%
——9——CVE-2025-23563—29.9%
——9——CVE-2008-0931—29.9%
——9——CVE-2026-504987.8 HIG29.9%
——9Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability59dCVE-2024-9027—29.9%
——9——CVE-2019-1966—29.9%
——9——CVE-2023-37488—29.9%
——9——CVE-2023-0639—29.9%
——9——CVE-2025-30354—29.9%
——9——CVE-2026-64866—29.9%
——9New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE /api/user/:id/reset_passkey, allowing a lower-privileged administrator to remove a passkey from a same-level or higher-privileged account, including a root account. This issue is fixed in version 1.0.0-rc.7.32dCVE-2024-9376—29.9%
——9——CVE-2026-846698.8 HIG29.9%
——9A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system.15dCVE-2025-23553—29.9%
——9——CVE-2010-1754—29.9%
——9——CVE-2025-6908—29.9%
——9——CVE-2022-505905.3 MED29.9%
——9SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.66dCVE-2024-11110—29.9%
——9——CVE-2019-1592—29.9%
——9——CVE-2025-23575—29.9%
——9——CVE-2025-61789—29.9%
——9——CVE-2026-25518—29.9%
——9——CVE-2025-58450—29.9%
——9——CVE-2025-9200—29.9%
——9——CVE-2025-23565—29.9%
——9——CVE-2022-0638—29.9%
——9——CVE-2025-45617—29.9%
——9——CVE-2025-23595—29.9%
——9——CVE-2023-3754—29.9%
——9——