Vulnerabilities exploitable today
372,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,229
- High8,230
- Medium6,226
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-51863—24.2%
——7——CVE-2024-7487—24.2%
——7——CVE-1999-1092—24.2%
——7——CVE-2025-24707—24.2%
——7——CVE-2025-24684—24.2%
——7——CVE-1999-1345—24.2%
——7——CVE-2021-0946—24.2%
——7——CVE-2025-24656—24.2%
——7——CVE-2026-27979.8 CRI24.2%
——7Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.59dCVE-2025-25891—24.2%
——7——CVE-2026-55517—24.2%
——7——CVE-2016-6089—24.2%
——7——CVE-2024-51879—24.2%
——7——CVE-2026-146145.4 MED24.2%
——7A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.32dCVE-2016-1773—24.2%
——7——CVE-2024-51866—24.2%
——7——CVE-2025-1118—24.2%
——7——CVE-2020-13626—24.2%
——7——CVE-2024-29916—24.2%
——7——CVE-2024-43999—24.2%
——7——CVE-2023-38723—24.2%
——7——CVE-2024-51893—24.1%
——7——CVE-2016-5927—24.2%
——7——CVE-2025-46740—24.2%
——7——CVE-2024-51892—24.2%
——7——CVE-2025-51533—24.2%
——7——CVE-2024-51870—24.2%
——7——CVE-2021-336257.5 HIG24.2%
——7An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.32dCVE-2026-29925—24.2%
——7——CVE-2025-553715.3 MED24.2%
——7Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.69dCVE-2016-5967—24.2%
——7——CVE-2010-5163—24.2%
——7——CVE-2024-51883—24.2%
——7——CVE-2024-51896—24.2%
——7——CVE-2024-31199—24.2%
——7——CVE-2025-23590—24.2%
——7——CVE-2025-553675.3 MED24.2%
——7Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.69dCVE-2024-51902—24.1%
——7——CVE-2024-51894—24.2%
——7——CVE-2025-24676—24.2%
——7——