Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-51695—26.7%
——8——CVE-2024-27996—26.7%
——8——CVE-2008-0990—26.7%
——8——CVE-2026-2083—26.7%
——8——CVE-2022-44758—26.7%
——8——CVE-2020-12354—26.7%
——8——CVE-2013-0947—26.7%
——8——CVE-2018-7928—26.7%
——8——CVE-2023-51370—26.7%
——8——CVE-2015-0663—26.7%
——8——CVE-2026-42844—26.7%
——8——CVE-2026-351828.8 HIG26.7%
——8Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-user-roles middleware. This allows any authenticated user to change account roles and promote themselves to Super Admin. This vulnerability is fixed in 2.0.6.53dCVE-2023-46824—26.7%
——8——CVE-1999-1042—26.7%
——8——CVE-2023-51691—26.7%
——8——CVE-2026-2212—26.7%
——8——CVE-2023-51548—26.7%
——8——CVE-2010-0064—26.7%
——8——CVE-2014-6518—26.7%
——8——CVE-2023-44479—26.7%
——8——CVE-2025-70063—26.7%
——8——CVE-2019-3688—26.7%
——8——CVE-2026-2199—26.7%
——8——CVE-2023-51534—26.7%
——8——CVE-2002-0303—26.7%
——8——CVE-2026-54011—26.7%
——8——CVE-2026-23484—26.7%
——8——CVE-2023-26930—26.7%
——8——CVE-2024-7241—26.7%
——8——CVE-2024-13557—26.7%
——8——CVE-2025-29489—26.7%
——8——CVE-2026-2217—26.7%
——8——CVE-2023-44265—26.7%
——8——CVE-2020-36311—26.6%
——8——CVE-2004-0320—26.6%
——8——CVE-2026-687527.2 HIG26.6%
——8A Project Resource Manager may gain broader administrative privileges under specific conditions.13dCVE-2024-28174—26.6%
——8——CVE-2021-21554—26.6%
——8——CVE-2004-2337—26.6%
——8——CVE-2023-30703—26.6%
——8——