Vulnerabilities exploitable today
372,253in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,277
- High8,394
- Medium6,440
- Low634
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2008-1692—23.1%
——7——CVE-2026-145259.4 CRI23.1%
——7IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.25dCVE-2024-57337—23.1%
——7——CVE-2023-4681—23.1%
——7——CVE-2024-36992—23.1%
——7——CVE-2024-20089—23.1%
——7——CVE-2025-48446—23.1%
——7——CVE-2025-32240—23.1%
——7——CVE-2024-25359—23.1%
——7——CVE-2024-56292—23.1%
——7——CVE-2024-35144—23.1%
——7——CVE-2025-24532—23.1%
——7——CVE-2024-57338—23.1%
——7——CVE-2025-12750—23.1%
——7——CVE-2025-7021—23.1%
——7——CVE-2022-41727—23.1%
——7——CVE-2006-1601—23.1%
——7——CVE-2025-35021—23.1%
——7——CVE-2013-5666—23.1%
——7——CVE-2004-0880—23.1%
——7——CVE-2024-56298—23.1%
——7——CVE-2017-12709—23.1%
——7——CVE-2024-5602—23.1%
——7——CVE-2025-32244—23.1%
——7——CVE-2025-49292—23.1%
——7——CVE-2025-2336—23.1%
——7——CVE-2026-424528.1 HIG23.1%
——7Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, /users/login issues a temporary JWT (temp_token) for TOTP-enabled accounts. That token carries a pendingTOTP state and should only be valid for the second-factor flow. However, the auth middleware accepts this token on regular authenticated endpoints. This effectively turns 2FA into single-factor (password) for impacted accounts. This issue has been patched in version 2.1.0.48dCVE-2026-73458.3 HIG23.1%
——7Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)49dCVE-2026-208267.8 HIG23.1%
——7Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.42dCVE-2025-3597—23.1%
——7——CVE-2025-1175—23.1%
——7——CVE-2024-22724—23.1%
——7——CVE-2020-27122—23.1%
——7——CVE-2026-41419—23.1%
——7——CVE-2025-27447—23.1%
——7——CVE-2024-56225—23.1%
——7——CVE-2025-32961—23.1%
——7——CVE-2024-11230—23.1%
——7——CVE-2024-52359—23.1%
——7——CVE-2025-1457—23.1%
——7——