Vulnerabilities exploitable today
372,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,229
- High8,230
- Medium6,226
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-51870—24.2%
——7——CVE-2025-46740—24.2%
——7——CVE-2024-51893—24.1%
——7——CVE-2025-553715.3 MED24.2%
——7Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.69dCVE-2025-22724—24.2%
——7——CVE-2016-5927—24.2%
——7——CVE-2026-26723—24.2%
——7——CVE-2024-4377—24.2%
——7——CVE-2026-33302—24.2%
——7——CVE-2022-20406—24.2%
——7——CVE-2025-24646—24.2%
——7——CVE-2025-24660—24.2%
——7——CVE-2025-24684—24.2%
——7——CVE-2025-12980—24.2%
——7——CVE-2025-0128—24.2%
——7——CVE-1999-1353—24.2%
——7——CVE-2025-23799—24.2%
——7——CVE-2020-5970—24.2%
——7——CVE-2002-1869—24.2%
——7——CVE-2024-51863—24.2%
——7——CVE-2025-15348—24.2%
——7——CVE-2019-15002—24.2%
——7——CVE-2021-0947—24.2%
——7——CVE-2020-5972—24.2%
——7——CVE-2025-23588—24.2%
——7——CVE-2018-19946—24.2%
——7——CVE-2025-23614—24.2%
——7——CVE-2026-170037.7 HIG24.2%
——7IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write.18dCVE-2019-8730—24.2%
——7——CVE-2025-8527—24.2%
——7——CVE-2026-29925—24.2%
——7——CVE-2021-336257.5 HIG24.2%
——7An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.32dCVE-2010-5163—24.2%
——7——CVE-2016-5967—24.2%
——7——CVE-2023-26385—24.2%
——7——CVE-2021-47914—24.2%
——7——CVE-2025-9108—24.2%
——7——CVE-2025-60458—24.2%
——7——CVE-2025-553665.3 MED24.2%
——7Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack.69dCVE-2023-22233—24.2%
——7——