Vulnerabilities exploitable today
373,224in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,252
- High8,221
- Medium6,136
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-8849—24.8%
——7——CVE-2024-56296—24.8%
——7——CVE-2026-40759—24.8%
——7——CVE-2025-46930—24.8%
——7——CVE-2018-1377—24.8%
——7——CVE-2024-31258—24.8%
——7——CVE-2025-27095—24.8%
——7——CVE-2026-33665—24.8%
——7——CVE-2026-54829—24.8%
——7——CVE-2025-47486—24.8%
——7——CVE-2025-46918—24.8%
——7——CVE-2023-2505—24.8%
——7——CVE-2025-0984—24.8%
——7——CVE-2025-11973—24.8%
——7——CVE-2025-46914—24.8%
——7——CVE-2025-7801—24.8%
——7——CVE-2026-40082—24.8%
——7——CVE-2024-38676—24.8%
——7——CVE-2024-51700—24.8%
——7——CVE-2025-64331—24.8%
——7——CVE-2010-0393—24.8%
——7——CVE-2025-49270—24.8%
——7——CVE-2009-5082—24.8%
——7——CVE-2024-40978—24.8%
——7——CVE-2019-6189—24.8%
——7——CVE-2025-64333—24.8%
——7——CVE-2026-35420—24.8%
——7——CVE-2026-203084.3 MED24.8%
——7A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.
This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.39dCVE-2025-11060—24.8%
——7——CVE-2026-54078—24.8%
——7veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/tools/DictionaryKeysHelper.java in getRichTextStringOrStreamEntryStringRepresentation(), where a crafted PDF containing a malicious rich-text /RC or /RV entry can cause external entity expansion and reflect local file contents into the validation report. This issue is fixed in versions 1.30.2 and 1.31.71.46dCVE-2026-28967—24.8%
——7——CVE-2024-32581—24.8%
——7——CVE-2025-24762—24.8%
——7——CVE-2024-40902—24.8%
——7——CVE-2025-59215—24.8%
——7——CVE-2026-2892—24.8%
——7——CVE-2025-69270—24.8%
——7——CVE-2023-5606—24.8%
——7——CVE-2025-55265—24.8%
——7——CVE-2024-21158—24.8%
——7——