Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-25607—25.6%
——8——CVE-2024-47389—25.6%
——8——CVE-2024-37487—25.6%
——8——CVE-2017-3276—25.6%
——8——CVE-2024-10679—25.6%
——8——CVE-2024-56237—25.6%
——8——CVE-2024-47369—25.6%
——8——CVE-2021-41528—25.6%
——8——CVE-2024-7590—25.6%
——8——CVE-2023-37398—25.6%
——8——CVE-2023-31229—25.6%
——8——CVE-2026-168536.5 MED25.6%
——8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.29dCVE-2025-5584—25.6%
——8——CVE-2026-78010—25.6%
——8A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.12dCVE-2024-41354—25.6%
——8——CVE-2026-23775—25.6%
——8——CVE-2025-5727—25.6%
——8——CVE-2024-6534—25.6%
——8——CVE-2026-185448.1 HIG25.6%
——8IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references.13dCVE-2025-13726—25.6%
——8——CVE-2021-25168—25.6%
——8——CVE-2022-26113—25.6%
——8——CVE-2025-3279—25.6%
——8——CVE-2025-8010—25.6%
——8——CVE-2020-9989—25.6%
——8——CVE-2016-5329—25.6%
——8——CVE-2017-8151—25.6%
——8——CVE-2022-49737—25.6%
——8——CVE-2021-25169—25.6%
——8——CVE-2017-1508—25.6%
——8——CVE-2025-52040—25.6%
——8——CVE-2021-30784—25.6%
——8——CVE-2026-598314.4 MED25.6%
——8GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS address, allowing a crafted vscode:// or vscode-insiders:// URL to be handed to VS Code. This issue is fixed in version 2.96.0.64dCVE-2026-601894.4 MED25.6%
——8Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).50dCVE-2024-10056—25.6%
——8——CVE-2021-25170—25.6%
——8——CVE-2024-12611—25.6%
——8——CVE-2018-0468—25.6%
——8——CVE-2025-8011—25.6%
——8——CVE-2024-22330—25.6%
——8——