Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,381
- High8,755
- Medium6,799
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-3844—29.6%
——9——CVE-2006-2452—29.6%
——9——CVE-2002-0334—29.6%
——9——CVE-2015-8086—29.6%
——9——CVE-2006-0431—29.6%
——9——CVE-2014-3917—29.6%
——9——CVE-2006-0190—29.6%
——9——CVE-2004-0047—29.6%
——9——CVE-2015-8893—29.6%
——9——CVE-2022-42410—29.6%
——9——CVE-2024-12324—29.6%
——9——CVE-2024-12394—29.6%
——9——CVE-2026-28125.3 MED29.6%
——9ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This issue affects ArcGIS Server 12.0 and earlier.57dCVE-2005-1064—29.6%
——9——CVE-2006-0427—29.6%
——9——CVE-2005-0205—29.6%
——9——CVE-2004-1353—29.6%
——9——CVE-2025-53003—29.6%
——9——CVE-2019-25518—29.6%
——9——CVE-2024-37958—29.6%
——9——CVE-2025-6466—29.6%
——9——CVE-2025-67998—29.6%
——9——CVE-2023-49852—29.6%
——9——CVE-2024-47827—29.6%
——9——CVE-2025-7936—29.6%
——9——CVE-2026-35611—29.6%
——9——CVE-2026-25126—29.6%
——9——CVE-2026-668028.1 HIG29.6%
——9Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.29dCVE-2007-5207—29.6%
——9——CVE-2026-482575.4 MED29.6%
——9Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.21dCVE-2023-43989—29.6%
——9——CVE-2014-3390—29.6%
——9——CVE-2024-12285—29.6%
——9——CVE-2026-418515.3 MED29.6%
——9Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.57dCVE-2023-30612—29.6%
——9——CVE-2023-32163—29.6%
——9——CVE-2017-17469—29.6%
——9——CVE-2023-33058—29.6%
——9——CVE-2024-13447—29.6%
——9——CVE-2026-917098.8 HIG29.6%
——9Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)1d