Vulnerabilities exploitable today
372,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,268
- High8,356
- Medium6,440
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-21503—23.5%
——7——CVE-2026-53811—23.5%
——7——CVE-2024-12472—23.5%
——7——CVE-2023-27434—23.5%
——7——CVE-2025-13295—23.5%
——7——CVE-2018-9466—23.5%
——7——CVE-2018-17955—23.5%
——7——CVE-2026-878178.8 HIG23.5%
——7GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.1dCVE-2026-637585.4 MED23.5%
——7SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. Attackers can issue KILL statements with target live query UUIDs to disrupt real-time data subscriptions of other users without ownership verification.51dCVE-2025-64049—23.5%
——7——CVE-2024-11382—23.5%
——7——CVE-2026-119155.9 MED23.5%
——7vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.60dCVE-2026-55890—23.5%
——7——CVE-2012-0054—23.5%
——7——CVE-2024-54002—23.5%
——7——CVE-2026-164566.5 MED23.5%
——7A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API keys and cloud credentials from other namespaces, leading to information disclosure.28dCVE-2018-6266—23.5%
——7——CVE-2026-32924—23.5%
——7——CVE-2025-12430—23.5%
——7——CVE-2023-26524—23.5%
——7——CVE-2023-52198—23.5%
——7——CVE-2017-12823—23.5%
——7——CVE-2024-47226—23.5%
——7——CVE-2023-47692—23.5%
——7——CVE-2023-28987—23.5%
——7——CVE-2024-20938—23.5%
——7——CVE-2023-28930—23.5%
——7——CVE-2024-20936—23.5%
——7——CVE-2021-31843—23.5%
——7——CVE-2026-1536—23.5%
——7——CVE-2023-22955—23.5%
——7——CVE-2022-38710—23.5%
——7——CVE-2024-11383—23.5%
——7——CVE-2023-25987—23.5%
——7——CVE-2025-2543—23.5%
——7——CVE-2023-5884—23.5%
——7——CVE-2025-600184.8 MED23.5%
——7glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read.73dCVE-2024-10320—23.5%
——7——CVE-2024-6727—23.5%
——7——CVE-2017-3225—23.5%
——7——