Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-51553—26.6%
——8——CVE-2025-46268—26.6%
——8——CVE-2025-10627—26.6%
——8——CVE-2025-11588—26.6%
——8——CVE-2023-31919—26.6%
——8——CVE-2025-10613—26.6%
——8——CVE-2024-45894—26.6%
——8——CVE-2015-1096—26.5%
——8——CVE-2021-45659—26.5%
——8——CVE-2026-12488—26.5%
——8——CVE-2024-29409—26.5%
——8——CVE-2026-34023—26.5%
——8——CVE-2023-2405—26.5%
——8——CVE-2026-41056—26.5%
——8——CVE-2025-2200—26.5%
——8——CVE-2026-598857.5 HIG26.5%
——8pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.57dCVE-2015-1094—26.5%
——8——CVE-2026-529327.5 HIG26.5%
——8In the Linux kernel, the following vulnerability has been resolved:
xfrm: ipcomp: Free destination pages on acomp errors
Move the out_free_req label up by a couple of lines so that the
allocated dst SG list gets freed on error as well as success.69dCVE-1999-1224—26.5%
——8——CVE-2026-101044.4 MED26.5%
——8The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_thumbnail Parameter in all versions up to, and including, 1.5.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.75dCVE-2025-59942—26.5%
——8——CVE-2020-27796—26.5%
——8——CVE-2026-27702—26.5%
——8——CVE-2025-0739—26.5%
——8——CVE-2026-1819—26.5%
——8——CVE-2019-3667—26.5%
——8——CVE-2023-37325—26.5%
——8——CVE-2026-43347—26.5%
——8——CVE-2025-62151—26.5%
——8——CVE-2025-56234—26.5%
——8——CVE-2026-8363—26.5%
——8——CVE-2026-45665—26.5%
——8——CVE-2026-32057—26.5%
——8——CVE-2024-5486—26.5%
——8——CVE-2020-6245—26.5%
——8——CVE-2026-32172—26.5%
——8——CVE-2024-4781—26.5%
——8——CVE-2020-5572—26.5%
——8——CVE-2025-11041—26.5%
——8——CVE-2023-28055—26.5%
——8——