Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,415
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-54097—25.7%
——8——CVE-2022-38510—25.7%
——8——CVE-2025-49250—25.7%
——8——CVE-2024-22727—25.7%
——8——CVE-2014-0974—25.7%
——8——CVE-2026-2554—25.7%
——8——CVE-2005-1124—25.7%
——8——CVE-2024-41596—25.7%
——8——CVE-2021-336278.2 HIG25.7%
——8An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.44.11, and 5.5 before 05.52.11 affecting FwBlockServiceSmm. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.35dCVE-2003-1010—25.7%
——8——CVE-2009-4997—25.7%
——8——CVE-2026-1352—25.7%
——8——CVE-2024-12403—25.7%
——8——CVE-2024-42163—25.7%
——8——CVE-2026-2462—25.7%
——8——CVE-2007-5921—25.7%
——8——CVE-2024-23215—25.7%
——8——CVE-2024-44798—25.7%
——8——CVE-2024-35224—25.7%
——8——CVE-2020-3889—25.7%
——8——CVE-2024-22603—25.7%
——8——CVE-2024-5470—25.7%
——8——CVE-2026-83617—25.7%
——8xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attribute name checks use the anchored QName_exact expression produced by reg() in lib/grammar.js, which inherits the multiline flag. A name with a valid first line followed by U+000A, U+000D, U+2028, or U+2029 and breakout markup therefore passes validation and is emitted verbatim in element start and end tags or attribute names. This bypasses the strict-serialization checks introduced for the earlier element-name and attribute-name injection advisories, while the default serialization path remains outside the strict guarantee. This issue is fixed in @xmldom/xmldom version 0.9.12.7dCVE-2024-28864—25.7%
——8——CVE-2026-108437.2 HIG25.7%
——8A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.55dCVE-2026-619679.8 CRI25.7%
——8Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.32dCVE-2025-634015.5 MED25.7%
——8Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives72dCVE-2026-3355—25.7%
——8——CVE-2024-41588—25.7%
——8——CVE-2021-4041—25.7%
——8——CVE-2023-6323—25.7%
——8——CVE-2024-6669—25.7%
——8——CVE-2023-42231—25.7%
——8——CVE-2025-10973—25.7%
——8——CVE-2025-69220—25.7%
——8——CVE-2025-10398—25.7%
——8——CVE-2024-2633—25.7%
——8——CVE-2023-25806—25.7%
——8——CVE-2025-3152—25.7%
——8——CVE-2021-38205—25.7%
——8——