Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,384
- High8,718
- Medium6,702
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-28863—28.3%
——8——CVE-2024-1965—28.3%
——8——CVE-2025-54719—28.3%
——8——CVE-2025-0645—28.3%
——8——CVE-2024-45699—28.3%
——8——CVE-2026-597968.1 HIG28.3%
——8In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks65dCVE-2022-27050—28.3%
——8——CVE-2023-47187—28.3%
——8——CVE-2025-54288—28.3%
——8——CVE-2026-134458.1 HIG28.3%
——8IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim file contents, appends attacker-controlled data, and uploads a copy containing victim data to the attacker's namespace (confidentiality breach). In overwrite mode, the attacker can replace victim file contents with arbitrary data (integrity breach). This breaks the storage ownership boundary between users.56dCVE-2025-43008—28.3%
——8——CVE-2025-10614—28.3%
——8——CVE-2023-51315—28.3%
——8——CVE-2026-874786.5 MED28.3%
——8Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)7dCVE-2025-9439—28.3%
——8——CVE-2025-58473—28.3%
——8——CVE-2025-24759—28.3%
——8——CVE-2026-27480—28.3%
——8——CVE-2025-0526—28.3%
——8——CVE-2024-12142—28.3%
——8——CVE-2026-674377.5 HIG28.3%
——8OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bounding entries, allowing an unauthenticated attacker to exhaust memory and cause a denial of service. This issue is fixed in version 3000.17.0.48dCVE-2026-1725—28.3%
——8——CVE-2024-31601—28.3%
——8——CVE-2025-9440—28.3%
——8——CVE-2025-26733—28.3%
——8——CVE-2026-31858—28.3%
——8——CVE-2026-31939—28.3%
——8——CVE-2026-585455.5 MED28.3%
——8Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.56dCVE-2026-41907—28.3%
——8——CVE-2026-54842—28.3%
——8——CVE-2025-5688—28.3%
——8——CVE-2026-162052.4 LOW28.3%
——8A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the argument Info can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.58dCVE-2025-22319—28.3%
——8——CVE-2023-46021—28.3%
——8——CVE-2024-47048—28.3%
——8——CVE-2026-13569—28.3%
——8——CVE-2025-6520—28.3%
——8——CVE-2023-3439—28.3%
——8——CVE-2024-6881—28.3%
——8——CVE-2025-23193—28.3%
——8——