Vulnerabilities exploitable today
372,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,273
- High8,389
- Medium6,464
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2005-1176—23.5%
——7——CVE-2007-5039—23.4%
——7——CVE-2026-527588.8 HIG23.4%
——7Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database.59dCVE-2024-31585—23.4%
——7——CVE-2018-6265—23.4%
——7——CVE-2024-25854—23.4%
——7——CVE-2024-0318—23.4%
——7——CVE-2024-2445—23.4%
——7——CVE-2024-30380—23.4%
——7——CVE-2007-0668—23.4%
——7——CVE-2023-36514—23.4%
——7——CVE-2026-163709.1 CRI23.4%
——7Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.49dCVE-2026-181418.2 HIG23.4%
——7A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.38dCVE-2018-4035—23.4%
——7——CVE-2026-188886.5 MED23.4%
——7The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user who can store data in a collection read through the BI Connector could use this to crash the application performing the read.14dCVE-2020-11923—23.4%
——7——CVE-2018-4046—23.4%
——7——CVE-2026-302506.1 MED23.4%
——7Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code2dCVE-2025-30953—23.4%
——7——CVE-2019-4140—23.4%
——7——CVE-2024-12062—23.4%
——7——CVE-2025-32465—23.4%
——7——CVE-2025-9708—23.4%
——7——CVE-2022-40291—23.4%
——7——CVE-2008-1754—23.4%
——7——CVE-2025-11611—23.4%
——7——CVE-2022-37394—23.4%
——7——CVE-2003-0880—23.4%
——7——CVE-2026-456547.9 HIG23.4%
——7Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.50dCVE-2018-4044—23.4%
——7——CVE-2025-1378—23.4%
——7——CVE-2024-13497—23.4%
——7——CVE-2025-11610—23.4%
——7——CVE-2018-4045—23.4%
——7——CVE-2025-47454—23.4%
——7——CVE-2026-694535.5 MED23.4%
——7Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.3dCVE-2025-47456—23.4%
——7——CVE-2026-168428.8 HIG23.4%
——7IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.18dCVE-2023-4393—23.4%
——7——CVE-2018-4033—23.4%
——7——