Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2006-4493—26.7%
——8——CVE-2003-1034—26.7%
——8——CVE-2006-0178—26.7%
——8——CVE-2024-34374—26.7%
——8——CVE-2024-7038—26.7%
——8Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.62dCVE-2004-0125—26.7%
——8——CVE-2022-36244—26.7%
——8——CVE-2006-3373—26.7%
——8——CVE-2025-377768.8 HIG26.7%
——8In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in smb_break_all_levII_oplock()
There is a room in smb_break_all_levII_oplock that can cause racy issues
when unlocking in the middle of the loop. This patch use read lock
to protect whole loop.48dCVE-2025-69806—26.7%
——8——CVE-2003-1291—26.7%
——8——CVE-2006-3634—26.7%
——8——CVE-2025-54092—26.7%
——8——CVE-2026-40480—26.7%
——8——CVE-2021-1840—26.7%
——8——CVE-2024-30185—26.7%
——8——CVE-2026-549928.4 HIG26.7%
——8Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.58dCVE-2025-22524—26.7%
——8——CVE-2026-861807.3 HIG26.7%
——8A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.8dCVE-2025-9399—26.7%
——8——CVE-2004-0134—26.7%
——8——CVE-2024-29811—26.7%
——8——CVE-2024-31448—26.7%
——8——CVE-2006-4787—26.7%
——8——CVE-2024-32593—26.7%
——8——CVE-2025-58012—26.7%
——8——CVE-2026-24139—26.7%
——8——CVE-2025-67564—26.7%
——8——CVE-2022-2719—26.7%
——8——CVE-2026-21949—26.7%
——8——CVE-2026-697134.4 MED26.7%
——8Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.6dCVE-2025-23828—26.7%
——8——CVE-2019-4448—26.7%
——8——CVE-2026-584685.5 MED26.7%
——8NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. Attackers can target loopback addresses, RFC-1918 private ranges, and cloud instance metadata endpoints to perform internal network port enumeration, host discovery, and retrieval of IAM role credentials from the instance metadata service. v2.1.18 added a warning message for when SERVER_REQUEST_WHITELIST is not configured.63dCVE-2026-44566—26.7%
——8——CVE-2025-54290—26.7%
——8——CVE-2025-5721—26.7%
——8——CVE-2025-66435—26.7%
——8——CVE-2024-29935—26.7%
——8——CVE-2008-2312—26.7%
——8——