Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,379
- High8,748
- Medium6,793
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-23862—29.8%
——9——CVE-2024-31099—29.8%
——9——CVE-2026-7735—29.8%
——9——CVE-2023-40197—29.8%
——9——CVE-2025-59454—29.8%
——9——CVE-2023-32578—29.8%
——9——CVE-2024-3071—29.8%
——9——CVE-2025-69197—29.8%
——9——CVE-2016-4627—29.8%
——9——CVE-2023-23817—29.8%
——9——CVE-2025-47985—29.8%
——9——CVE-2024-45999—29.8%
——9——CVE-2024-6938—29.8%
——9——CVE-2024-10214—29.8%
——9——CVE-2023-33859—29.8%
——9——CVE-2023-37994—29.8%
——9——CVE-2023-23699—29.8%
——9——CVE-2024-8771—29.8%
——9——CVE-2023-23867—29.8%
——9——CVE-2022-46844—29.8%
——9——CVE-2025-30592—29.8%
——9——CVE-2023-27619—29.8%
——9——CVE-2023-38516—29.8%
——9——CVE-2025-31710—29.8%
——9——CVE-2026-170818.2 HIG29.8%
——9IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.29dCVE-2024-39867—29.8%
——9——CVE-2025-57613—29.8%
——9——CVE-2023-30482—29.8%
——9——CVE-2022-3750—29.8%
——9——CVE-2023-23709—29.8%
——9——CVE-2023-23826—29.8%
——9——CVE-2026-58071—29.8%
——9A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.15dCVE-2026-629607.4 HIG29.8%
——9Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-HTTP(S) values are treated as local filesystem paths, and file URI prefixes are removed, so a bare UNC path or file URI targeting an attacker-controlled share causes Windows to initiate an outbound SMB connection. This can expose NTLM authentication material to the attacker-selected host. This issue is fixed in version 2.55.0.windows.4.23dCVE-2023-39988—29.8%
——9——CVE-2020-2927—29.8%
——9——CVE-2024-30463—29.8%
——9——CVE-2023-0592—29.8%
——9——CVE-2026-117636.5 MED29.8%
——9Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers.
This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.63dCVE-2025-0662—29.8%
——9——CVE-2026-854558.2 HIG29.8%
——9MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication.10d