Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-1208—27.1%
——8——CVE-2025-53408—27.1%
——8——CVE-2024-4277—27.1%
——8——CVE-2024-13318—27.1%
——8——CVE-2024-7783—27.1%
——8——CVE-2025-69195—27.1%
——8——CVE-2026-729228.2 HIG27.1%
——8AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from the untrusted provider URL segment without verifying webhook.provider, allowing a request to /compass/webhooks/{webhook_id}/ingress to use CompassWebhookManager's inherited no-op BaseWebhooksManager.verify_signature instead of GenericWebhooksManager.verify_signature, bypass X-Webhook-Secret for a configured secret_token, and execute a generic webhook graph as its owner. This issue is fixed in version 0.6.70.7dCVE-2023-41068—27.1%
——8——CVE-2025-13440—27.1%
——8——CVE-2014-2485—27.1%
——8——CVE-2022-25153—27.1%
——8——CVE-2024-45453—27.1%
——8——CVE-2020-4197—27.1%
——8——CVE-2019-4112—27.1%
——8——CVE-2025-10291—27.1%
——8——CVE-2026-57319.8 CRI27.1%
——8Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.63dCVE-2018-17502—27.1%
——8——CVE-2024-12513—27.1%
——8——CVE-2013-1425—27.1%
——8——CVE-2024-1759—27.1%
——8——CVE-2026-406118.8 HIG27.1%
——8Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A malicious ACME server can supply a crafted challenge token containing ../ sequences, causing lego to write attacker-influenced content to any path writable by the lego process. This vulnerability is fixed in 4.34.0.63dCVE-2025-0368—27.1%
——8——CVE-2010-1488—27.1%
——8——CVE-2025-32599—27.1%
——8——CVE-2024-2841—27.1%
——8——CVE-2010-4819—27.1%
——8——CVE-2024-10956—27.1%
——8——CVE-2022-42851—27.1%
——8——CVE-2024-442867.5 HIG27.1%
——8This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access can input keyboard events to apps running on a locked device.54dCVE-2020-21881—27.1%
——8——CVE-2025-32600—27.1%
——8——CVE-2024-47549—27.1%
——8——CVE-2013-1958—27.1%
——8——CVE-2024-56219—27.1%
——8——CVE-2025-3471—27.1%
——8——CVE-2016-6162—27.1%
——8——CVE-2020-7453—27.1%
——8——CVE-2024-12034—27.1%
——8——CVE-2024-43384—27.1%
——8——CVE-2010-3095—27.1%
——8——