Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-8679—27.1%
——8——CVE-2022-39996—27.1%
——8——CVE-2024-13125—27.1%
——8——CVE-2024-3890—27.1%
——8——CVE-2025-47930—27.1%
——8——CVE-2025-36074—27.1%
——8——CVE-2025-47748—27.1%
——8——CVE-2021-21518—27.1%
——8——CVE-2026-73085—27.1%
——8Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens on API and WebSocket resource endpoints such as /api/me instead of restricting them to /auth/refresh, allowing refresh tokens to authenticate as the associated users. This issue is fixed in version 2.36.0.7dCVE-2025-8265—27.1%
——8——CVE-2008-6756—27.1%
——8——CVE-2010-4337—27.1%
——8——CVE-2024-29122—27.1%
——8——CVE-2024-53818—27.1%
——8——CVE-2022-48019—27.1%
——8——CVE-2025-20329—27.1%
——8——CVE-2026-178688.8 HIG27.1%
——8Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)44dCVE-2024-4481—27.1%
——8——CVE-2021-26277—27.1%
——8——CVE-2024-31121—27.1%
——8——CVE-2025-12623—27.1%
——8——CVE-2025-44560—27.1%
——8——CVE-2021-34949—27.1%
——8——CVE-2016-5615—27.1%
——8——CVE-2025-22243—27.1%
——8——CVE-2026-25982—27.1%
——8——CVE-2024-31104—27.1%
——8——CVE-2024-4275—27.1%
——8——CVE-2019-18381—27.1%
——8——CVE-2020-16122—27.1%
——8——CVE-2021-34972—27.1%
——8——CVE-2024-12173—27.1%
——8——CVE-2024-4339—27.1%
——8——CVE-2024-2536—27.1%
——8——CVE-2024-25936—27.1%
——8——CVE-2024-30422—27.1%
——8——CVE-2026-355383.1 LOW27.1%
——8An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.53dCVE-2021-35246—27.1%
——8——CVE-2018-0092—27.1%
——8——CVE-2024-12263—27.1%
——8——