Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,753
- Medium6,799
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-48174—29.6%
——9——CVE-2026-482545.4 MED29.6%
——9Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.21dCVE-2023-43997—29.6%
——9——CVE-2024-31236—29.6%
——9——CVE-2026-673217.5 HIG29.6%
——9axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.17dCVE-2024-1942—29.6%
——9——CVE-2022-38662—29.6%
——9——CVE-2007-5207—29.6%
——9——CVE-2025-363276.5 MED29.6%
——9IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actions due to client-side enforcement of sever-side security.74dCVE-2019-25518—29.6%
——9——CVE-2025-67998—29.6%
——9——CVE-2025-53003—29.6%
——9——CVE-2019-11087—29.6%
——9——CVE-2024-40684—29.6%
——9——CVE-2024-47827—29.6%
——9——CVE-2025-6466—29.6%
——9——CVE-2024-37958—29.6%
——9——CVE-2023-49852—29.6%
——9——CVE-2024-33920—29.6%
——9——CVE-2026-25969—29.6%
——9——CVE-2025-11974—29.6%
——9——CVE-2026-07164.8 MED29.6%
——9A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.2dCVE-2025-57922—29.6%
——9——CVE-2023-2960—29.6%
——9——CVE-2025-40925—29.6%
——9——CVE-2021-44196—29.6%
——9——CVE-2026-581897.5 HIG29.6%
——9Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.46dCVE-2024-33748—29.6%
——9——CVE-2005-0069—29.6%
——9——CVE-2026-827879.8 CRI29.6%
——9Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.2dCVE-2022-42381—29.6%
——9——CVE-2023-5116—29.6%
——9——CVE-2005-0503—29.6%
——9——CVE-2024-10322—29.6%
——9——CVE-2010-4707—29.6%
——9——CVE-2014-6595—29.6%
——9——CVE-2023-43992—29.6%
——9——CVE-2026-109458.8 HIG29.6%
——9Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)58dCVE-2026-28125.3 MED29.6%
——9ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This issue affects ArcGIS Server 12.0 and earlier.57dCVE-2024-12394—29.6%
——9——