Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-8266—25.0%
——8——CVE-2024-50627—25.0%
——8——CVE-2026-23990—25.0%
——8——CVE-2026-563334.3 MED25.0%
——8Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allows authenticated org admins to persist invalid security policy state. Attackers can bypass backend validation by directly updating the public.orgs table from the browser, circumventing field-level validation checks for max_apikey_expiration_days and other security-sensitive configuration parameters.76dCVE-2025-60118—25.0%
——8——CVE-2026-542777.5 HIG25.0%
——8AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using the optimised C parser (the default in pre-built wheels), then an attacker may be able to send oversized lines through the HTTP parser and use an excessive amount of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.77dCVE-2007-5023—25.0%
——8——CVE-2025-26918—25.0%
——8——CVE-2024-45108—25.0%
——8——CVE-2019-6601—25.0%
——8——CVE-2019-4266—25.0%
——8——CVE-2020-23967—25.0%
——8——CVE-2025-4887—25.0%
——8——CVE-2021-2147—25.0%
——8——CVE-2025-30171—25.0%
——8——CVE-2025-10391—25.0%
——8——CVE-2025-8770—25.0%
——8——CVE-2025-9041—25.0%
——8——CVE-2025-62362—25.0%
——8——CVE-2024-38037—25.0%
——8——CVE-2024-49541—25.0%
——8——CVE-2024-9199—25.0%
——8——CVE-2024-48396—25.0%
——8——CVE-2024-49633—25.0%
——8——CVE-2025-10163—25.0%
——8——CVE-2023-34370—25.0%
——8——CVE-2023-4255—25.0%
——8——CVE-2025-21401—25.0%
——8——CVE-2025-3009—25.0%
——8——CVE-2020-12337—25.0%
——8——CVE-2026-30235—25.0%
——8——CVE-2026-25809—25.0%
——8——CVE-2024-10085—25.0%
——8CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are sent to the platform.14dCVE-2025-24703—25.0%
——8——CVE-2019-1919—25.0%
——8——CVE-2025-11627—25.0%
——8——CVE-2026-206227.5 HIG25.0%
——8A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to capture a user's screen.25dCVE-2025-37131—25.0%
——8——CVE-2025-47776—25.0%
——8——CVE-2025-11224—25.0%
——8——