Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-31136—29.2%
——9——CVE-2025-10615—29.2%
——9——CVE-2022-2389—29.2%
——9——CVE-2017-0741—29.2%
——9——CVE-2025-25497—29.2%
——9——CVE-2017-8277—29.2%
——9——CVE-2024-47789—29.2%
——9——CVE-2017-0731—29.2%
——9——CVE-2020-12304—29.2%
——9——CVE-2012-3516—29.2%
——9——CVE-2017-9720—29.2%
——9——CVE-2019-11139—29.2%
——9——CVE-2024-35720—29.2%
——9——CVE-2025-14934—29.2%
——9——CVE-2025-48743—29.2%
——9——CVE-2012-4606—29.2%
——9——CVE-2024-20364—29.2%
——9——CVE-2024-35725—29.2%
——9——CVE-2025-1190—29.2%
——9——CVE-2017-8271—29.2%
——9——CVE-2012-4461—29.2%
——9——CVE-2013-10075—29.2%
——9——CVE-2017-8272—29.2%
——9——CVE-2025-63910—29.2%
——9——CVE-2010-2431—29.2%
——9——CVE-2023-1279—29.2%
——9——CVE-2017-0742—29.2%
——9——CVE-2017-8256—29.2%
——9——CVE-2026-42251—29.2%
——9Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate update.
This issue affects KS-SOMED with modules: KSPLUPDFTP.exe up to 30.00.00.056 and ANEKSKLIENT.EXE up to 29.00.02.026
Beside removing the hard-coded credentials from the code and changing the update process, access granted by previously exposed credentials was limited to read-only.58dCVE-2017-8261—29.2%
——9——CVE-2008-0242—29.2%
——9——CVE-2017-0729—29.2%
——9——CVE-2024-35721—29.2%
——9——CVE-2024-28582—29.2%
——9——CVE-2023-24605—29.2%
——9——CVE-2025-13185—29.2%
——9——CVE-2026-39958—29.2%
——9——CVE-2006-7160—29.2%
——9——CVE-2026-155728.8 HIG29.2%
——9A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.38dCVE-2024-35669—29.2%
——9——