Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,217
- High8,129
- Medium6,162
- Low606
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-41905—22.9%
——7——CVE-2020-25234—22.9%
——7——CVE-2021-25263—22.9%
——7——CVE-2025-46175—22.9%
——7——CVE-2022-21704—22.9%
——7——CVE-2026-5242—22.9%
——7——CVE-2024-6979—22.9%
——7——CVE-2026-400376.5 MED22.9%
——7OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering redirects to exfiltrate sensitive request data or headers to unintended origins.48dCVE-2026-40407—22.9%
——7——CVE-2023-7237—22.9%
——7——CVE-2024-40906—22.9%
——7——CVE-2024-24768—22.9%
——7——CVE-2024-11353—22.9%
——7——CVE-2024-6325—22.9%
——7——CVE-2025-30317—22.9%
——7——CVE-2023-44853—22.9%
——7——CVE-2018-3634—22.9%
——7——CVE-2026-5002—22.9%
——7——CVE-2026-44349—22.9%
——7——CVE-2025-46335—22.9%
——7——CVE-2023-34471—22.9%
——7——CVE-2011-2311—22.9%
——7——CVE-2024-34123—22.9%
——7——CVE-2024-583795.3 MED22.9%
——7nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny service.11dCVE-2014-0406—22.9%
——7——CVE-2021-29649—22.9%
——7——CVE-2013-4373—22.9%
——7——CVE-2026-32947—22.9%
——7——CVE-2026-102807.3 HIG22.9%
——7A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file client/src/app/api/mcp/call/route.ts of the component MCP API Call Endpoint. The manipulation of the argument serverBaseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.51dCVE-2023-23428—22.9%
——7——CVE-2026-102217.3 HIG22.9%
——7A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.51dCVE-2025-66400—22.9%
——7——CVE-2024-39900—22.9%
——7——CVE-2025-26262—22.9%
——7——CVE-2024-51741—22.9%
——7——CVE-2026-42084—22.9%
——7——CVE-2019-25531—22.9%
——7——CVE-2026-79776—22.9%
——7——CVE-2023-47466—22.9%
——7——CVE-2025-46174—22.9%
——7——