Vulnerabilities exploitable today
373,224in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,252
- High8,221
- Medium6,136
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-1377—24.8%
——7——CVE-2024-40978—24.8%
——7——CVE-2026-33665—24.8%
——7——CVE-2025-47486—24.8%
——7——CVE-2025-27095—24.8%
——7——CVE-2026-54829—24.8%
——7——CVE-2025-8849—24.8%
——7——CVE-2024-56296—24.8%
——7——CVE-2025-46918—24.8%
——7——CVE-2025-46914—24.8%
——7——CVE-2010-0393—24.8%
——7——CVE-2023-2505—24.8%
——7——CVE-2025-0984—24.8%
——7——CVE-2025-11973—24.8%
——7——CVE-2026-33480—24.8%
——7——CVE-2026-7094—24.8%
——7——CVE-2026-695595.8 MED24.8%
——7Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.5dCVE-2025-46966—24.8%
——7——CVE-2024-38696—24.8%
——7——CVE-2026-1656—24.8%
——7——CVE-2025-46943—24.8%
——7——CVE-2025-46963—24.8%
——7——CVE-2025-47078—24.8%
——7——CVE-2025-0679—24.8%
——7——CVE-2025-64333—24.8%
——7——CVE-2026-24851—24.8%
——7——CVE-2019-6189—24.8%
——7——CVE-2022-42866—24.8%
——7——CVE-2026-647786.5 MED24.8%
——7The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Visiting a maliciously crafted website may leak sensitive data.27dCVE-2025-46972—24.8%
——7——CVE-2025-46977—24.8%
——7——CVE-2026-86435.5 MED24.8%
——7pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.5dCVE-2025-46968—24.8%
——7——CVE-2018-254248.2 HIG24.8%
——7Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST requests to login-exec.php with SQL injection payloads in form parameters to authenticate without valid credentials and gain access to the application.54dCVE-2025-26526—24.8%
——7——CVE-2003-0480—24.8%
——7——CVE-2026-40758—24.8%
——7——CVE-2025-46945—24.8%
——7——CVE-2025-46942—24.8%
——7——CVE-2024-56299—24.8%
——7——