Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,215
- High7,863
- Medium6,398
- Low708
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-11574—28.0%
——8——CVE-2025-49191—28.0%
——8——CVE-2018-25187—28.0%
——8——CVE-2024-8670—27.9%
——8——CVE-2026-56061—27.9%
——8——CVE-2026-5394—27.9%
——8——CVE-2022-38801—27.9%
——8——CVE-2024-23516—27.9%
——8——CVE-2026-6620—27.9%
——8——CVE-2025-59833—27.9%
——8——CVE-2024-582398.2 HIG27.9%
——8In the Linux kernel, the following vulnerability has been resolved:
tls: stop recv() if initial process_rx_list gave us non-DATA
If we have a non-DATA record on the rx_list and another record of the
same type still on the queue, we will end up merging them:
- process_rx_list copies the non-DATA record
- we start the loop and process the first available record since it's
of the same type
- we break out of the loop since the record was not DATA
Just check the record type and jump to the end in case process_rx_list
did some work.43dCVE-2026-619547.5 HIG27.9%
——8Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.55dCVE-2019-1588—27.9%
——8——CVE-2024-13854—27.9%
——8——CVE-2014-0058—27.9%
——8——CVE-2025-22516—27.9%
——8——CVE-2025-24673—27.9%
——8——CVE-2026-3773—27.9%
——8——CVE-2023-21618—27.9%
——8——CVE-2026-54832—27.9%
——8——CVE-2026-1160—27.9%
——8——CVE-2026-54844—27.9%
——8——CVE-2020-37203—27.9%
——8——CVE-2025-4068—27.9%
——8——CVE-2024-56800—27.9%
——8——CVE-2026-56025—27.9%
——8——CVE-2023-47020—27.9%
——8——CVE-2025-22529—27.9%
——8——CVE-2025-57353—27.9%
——8——CVE-2025-24678—27.9%
——8——CVE-2026-54830—27.9%
——8——CVE-2024-34453—27.9%
——8——CVE-2025-8093—27.9%
——8——CVE-2025-53717—27.9%
——8——CVE-2025-41000—27.9%
——8——CVE-2025-62856—27.9%
——8——CVE-2020-37202—27.9%
——8——CVE-2020-8721—27.9%
——8——CVE-2024-8492—27.9%
——8——CVE-2026-34292—27.9%
——8——