Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,381
- High8,702
- Medium6,686
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-5056—28.5%
——9——CVE-2025-63058—28.5%
——9——CVE-2024-29766—28.5%
——9——CVE-2025-2830—28.5%
——9——CVE-2024-29798—28.5%
——9——CVE-2025-52468—28.5%
——9——CVE-2010-1487—28.5%
——9——CVE-2015-1085—28.5%
——9——CVE-2024-29801—28.5%
——9——CVE-2024-6061—28.5%
——9——CVE-2024-29762—28.5%
——9——CVE-2019-4381—28.5%
——9——CVE-2026-31931—28.5%
——9——CVE-2019-19594.4 MED28.5%
——9Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.23dCVE-2020-8756—28.5%
——9——CVE-2024-29154—28.5%
——9——CVE-2020-0587—28.5%
——9——CVE-2024-12834—28.4%
——9——CVE-2026-75297.5 HIG28.5%
——9The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for unauthenticated attackers to read and modify the plugin's banner, stockbar, and core settings — including saving/updating banner records, toggling stockbar/feature flags, changing the active banner, and uploading background-image files via wp_handle_upload() — without any nonce or capability check.35dCVE-2026-9509—28.5%
——9An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST requests to the ‘/api/migration’ endpoint. This request triggers a failure that halts critical processes, leaving the system offline until the services or server are manually restarted. As a result, access control readers cease to function, and potential failures may occur in third-party integrations. Since the exploit requires no privileges or user interaction and is trivial to automate, the impact on availability is high, and the effect extends to interconnected systems.57dCVE-2026-31933—28.5%
——9——CVE-2020-0593—28.5%
——9——CVE-2025-58737—28.5%
——9——CVE-2026-12043—28.5%
——9——CVE-2026-38530—28.5%
——9——CVE-2021-4268—28.5%
——9——CVE-2024-32081—28.5%
——9——CVE-2022-32872—28.5%
——9——CVE-2002-0790—28.5%
——9——CVE-2007-5024—28.5%
——9——CVE-2016-4593—28.5%
——9——CVE-2009-0024—28.5%
——9——CVE-2015-1113—28.5%
——9——CVE-2023-41240—28.5%
——9——CVE-2025-26886—28.5%
——9——CVE-2000-0334—28.5%
——9——CVE-2025-14783—28.5%
——9——CVE-2023-28775—28.5%
——9——CVE-2026-02837.2 HIG28.5%
——9An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection.
Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.36dCVE-2024-29769—28.5%
——9——