Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-27379—29.5%
——9——CVE-2024-28805—29.5%
——9——CVE-2024-12622—29.5%
——9——CVE-2024-41809—29.5%
——9——CVE-2023-37538—29.5%
——9——CVE-2023-388997.8 HIG29.5%
——9SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.71dCVE-2023-41949—29.5%
——9——CVE-2023-47073—29.5%
——9——CVE-2017-1301—29.5%
——9——CVE-2025-46573—29.5%
——9——CVE-2007-3771—29.5%
——9——CVE-2026-342097.5 HIG29.5%
——9mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative close handler validated the close voucher amount using "<" instead of "<=" against the on-chain settled amount. An attacker could submit a close voucher exactly equal to the settled amount, which would be accepted without committing any new funds, effectively closing or griefing the channel for free. This issue has been patched in version 0.4.11.55dCVE-2025-53789—29.5%
——9——CVE-2025-20368—29.5%
——9——CVE-2023-43052—29.5%
——9——CVE-2026-874317.5 HIG29.5%
——9Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)7dCVE-2023-6813—29.5%
——9——CVE-2024-25707—29.5%
——9——CVE-2026-30761—29.5%
——9——CVE-2024-11207—29.5%
——9——CVE-2026-172594.3 MED29.5%
——9IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.10dCVE-2024-20757—29.5%
——9——CVE-2024-12506—29.5%
——9——CVE-2023-4828—29.5%
——9——CVE-2025-13021—29.5%
——9——CVE-2023-51727—29.5%
——9——CVE-2025-49978—29.5%
——9——CVE-2023-51732—29.5%
——9——CVE-2025-12331—29.5%
——9——CVE-2023-47524—29.5%
——9——CVE-2023-0760—29.5%
——9——CVE-2026-200398.6 HIG29.5%
——9A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to ineffective memory management of the VPN web server. An attacker could exploit this vulnerability by sending a large number of crafted HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.37dCVE-2025-53835—29.5%
——9——CVE-2025-15276—29.5%
——9——CVE-2022-39427—29.5%
——9——CVE-2023-20249—29.5%
——9——CVE-2002-0165—29.5%
——9——CVE-2010-3159—29.5%
——9——CVE-1999-1126—29.5%
——9——CVE-2005-0120—29.5%
——9——