Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,276
- High8,382
- Medium6,420
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-3437—23.1%
——7——CVE-2026-2867—23.1%
——7——CVE-2025-1461—23.1%
——7——CVE-2025-13289—23.1%
——7——CVE-2026-34751—23.1%
——7——CVE-2025-30924—23.1%
——7——CVE-2025-68662—23.1%
——7——CVE-2025-13347—23.1%
——7——CVE-2026-0110—23.1%
——7——CVE-2025-30579—23.1%
——7——CVE-2024-32924—23.1%
——7——CVE-2023-31033—23.0%
——7——CVE-2021-30738—23.0%
——7——CVE-2026-195918.8 HIG23.0%
——7OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex follows its instructions, Codex can run a file-writing Git command without requesting user approval. On macOS and Linux, exploitation additionally requires separately installed PowerShell Core (pwsh) to be invoked. If filesystem protections permit the write, the command can modify Codex's configuration. If Codex later loads the modified configuration, it can launch an attacker-controlled MCP server and execute code with the user's privileges, allowing it to read, change, or delete files accessible to that account. The approval bypass does not disable filesystem sandboxing; the default filesystem sandbox on macOS and Linux can prevent writes outside permitted locations.8dCVE-2023-28016—23.0%
——7——CVE-2026-3651—23.0%
——7——CVE-2020-12702—23.0%
——7——CVE-2025-45818—23.0%
——7——CVE-2017-13810—23.0%
——7——CVE-2026-536666.1 MED23.0%
——7React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0.39dCVE-2024-45511—23.0%
——7——CVE-2019-15471—23.0%
——7——CVE-2025-14130—23.0%
——7——CVE-2026-109178.3 HIG23.0%
——7Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)50dCVE-2016-7614—23.0%
——7——CVE-2026-27316—23.0%
——7——CVE-2026-25198—23.0%
——7——CVE-2023-35006—23.0%
——7——CVE-2025-14629—23.0%
——7——CVE-2025-11715—23.0%
——7——CVE-2025-57954—23.0%
——7——CVE-2026-6592—23.0%
——7——CVE-2026-130825.3 MED23.0%
——7GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets.
The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string.
The built-in rand function is unsuitable for security applications because it is predictable and reversible.55dCVE-2006-5215—23.0%
——7——CVE-2013-4235—23.0%
——7——CVE-2024-1724—23.0%
——7——CVE-2024-554025.3 MED23.0%
——74C Strategies Exonaut before v22.4 was discovered to contain an access control issue.68dCVE-2026-3061—23.0%
——7——CVE-2010-4000—23.0%
——7——CVE-2024-32713—23.0%
——7——