Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2014-2485—27.1%
——8——CVE-2026-28450—27.1%
——8——CVE-2024-45453—27.1%
——8——CVE-2023-4523—27.1%
——8——CVE-2023-28640—27.1%
——8——CVE-2019-4112—27.1%
——8——CVE-2024-2841—27.1%
——8——CVE-2025-53428—27.1%
——8——CVE-2026-406118.8 HIG27.1%
——8Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A malicious ACME server can supply a crafted challenge token containing ../ sequences, causing lego to write attacker-influenced content to any path writable by the lego process. This vulnerability is fixed in 4.34.0.63dCVE-2025-12924—27.1%
——8——CVE-2024-2936—27.1%
——8——CVE-2025-0368—27.1%
——8——CVE-2025-32599—27.1%
——8——CVE-2024-47271—27.1%
——8——CVE-2009-3894—27.1%
——8——CVE-2025-23393—27.1%
——8——CVE-2019-4177—27.1%
——8——CVE-2017-14426—27.1%
——8——CVE-1999-1276—27.1%
——8——CVE-2019-18181—27.1%
——8——CVE-2017-14427—27.1%
——8——CVE-2012-3381—27.1%
——8——CVE-2024-1808—27.1%
——8——CVE-2024-56335—27.1%
——8——CVE-2000-0249—27.1%
——8——CVE-2024-2457—27.1%
——8——CVE-2024-2120—27.1%
——8——CVE-2018-12198—27.1%
——8——CVE-2021-20178—27.1%
——8——CVE-2026-27768—27.1%
——8——CVE-2025-55895—27.1%
——8——CVE-2026-33130—27.1%
——8——CVE-2020-8478—27.1%
——8——CVE-2010-2058—27.1%
——8——CVE-2024-47801—27.1%
——8——CVE-2009-4642—27.1%
——8——CVE-2007-3850—27.1%
——8——CVE-2024-1054—27.1%
——8——CVE-2025-1977—27.1%
——8——CVE-2025-32601—27.1%
——8——