Vulnerabilities exploitable today
356,393in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603
Distribution · last window
- Critical2,787
- High11,164
- Medium7,399
- Low700
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-1999-0264—92.5%
——28——CVE-2020-13576—92.5%
——28——CVE-2006-3533—92.5%
——28——CVE-2010-3824—92.5%
——28——CVE-2003-0509—92.5%
——28——CVE-2019-17186—92.5%
——28——CVE-2019-13548—92.5%
——28——CVE-2006-0806—92.5%
——28——CVE-2018-7081—92.5%
——28——CVE-2008-4231—92.5%
——28——CVE-2017-8023—92.5%
——28——CVE-2010-0689—92.5%
——28——CVE-2002-2032—92.5%
——28——CVE-2026-290009.1 CRI92.5%
——28pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.23dCVE-2010-3805—92.5%
——28——CVE-2014-3688—92.5%
——28——CVE-2011-1824—92.5%
——28——CVE-2020-1025—92.5%
——28——CVE-2002-2379—92.5%
——28——CVE-2006-1584—92.5%
——28——CVE-2018-12455—92.5%
——28——CVE-2017-5607—92.5%
——28——CVE-2009-3536—92.5%
——28——CVE-2008-2363—92.5%
——28——CVE-2007-3208—92.5%
——28——CVE-2012-0772—92.5%
——28——CVE-2006-3888—92.5%
——28——CVE-2020-1232—92.5%
——28——CVE-2015-4003—92.5%
——28——CVE-2007-4758—92.5%
——28——CVE-2009-2384—92.5%
——28——CVE-2011-1705—92.5%
——28——CVE-2011-1706—92.5%
——28——CVE-2002-0684—92.5%
——28——CVE-2011-1708—92.5%
——28——CVE-2015-2724—92.5%
——28——CVE-1999-0229—92.5%
——28——CVE-2008-5014—92.5%
——28——CVE-2000-0706—92.5%
——28——CVE-2005-0952—92.5%
——28——