Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,210
- High7,849
- Medium6,389
- Low708
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-8365—28.1%
——8——CVE-2025-58120—28.1%
——8——CVE-2003-0986—28.1%
——8——CVE-2024-46963—28.1%
——8——CVE-2002-0939—28.1%
——8——CVE-2026-27888—28.1%
——8——CVE-2026-84855.9 MED28.1%
——8Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation.
This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.55dCVE-2024-5770—28.1%
——8——CVE-2000-0366—28.1%
——8——CVE-2026-449365.0 MED28.1%
——8Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml file, allowing attackers able to push to fleet monitored git repos to leak helm access credentials.69dCVE-2023-43952—28.1%
——8——CVE-2026-129659.1 CRI28.1%
——8The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.16dCVE-2007-4998—28.1%
——8——CVE-2009-0319—28.1%
——8——CVE-2016-10139—28.1%
——8——CVE-2023-43951—28.1%
——8——CVE-2019-10420—28.1%
——8——CVE-2019-14395—28.1%
——8——CVE-2026-49162.7 LOW28.1%
——8GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.54dCVE-2025-48592—28.1%
——8——CVE-2016-6341—28.1%
——8——CVE-2022-42070—28.1%
——8——CVE-2023-42897—28.1%
——8——CVE-2026-25898—28.1%
——8——CVE-2024-13596—28.1%
——8——CVE-2026-57873—28.1%
——8——CVE-2024-12323—28.1%
——8——CVE-2016-9730—28.1%
——8——CVE-2023-20884—28.1%
——8——CVE-2025-45529—28.1%
——8——CVE-2026-694507.8 HIG28.1%
——8Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally.8dCVE-2025-14518—28.1%
——8——CVE-2024-25399—28.1%
——8——CVE-2026-33597—28.1%
——8——CVE-2026-31963—28.1%
——8——CVE-2025-1293—28.1%
——8——CVE-2026-694367.8 HIG28.1%
——8Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.7dCVE-2020-10699—28.1%
——8——CVE-2022-39182—28.1%
——8——CVE-2025-49653—28.1%
——8——