Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low585
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-1930—22.0%
——7——CVE-2022-35101—22.0%
——7——CVE-2023-37238—22.0%
——7——CVE-2025-43358—22.0%
——7——CVE-2017-9079—22.0%
——7——CVE-2024-51861—22.0%
——7——CVE-2024-51911—22.0%
——7——CVE-2025-12942—22.0%
——7——CVE-2026-479197.8 HIG22.0%
——7Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.12dCVE-2025-2924—22.0%
——7——CVE-2025-2915—22.0%
——7——CVE-2024-4154—22.0%
——7——CVE-2023-36482—22.0%
——7——CVE-2022-35106—22.0%
——7——CVE-2024-37172—22.0%
——7——CVE-2023-47616—22.0%
——7——CVE-2024-13019—22.0%
——7——CVE-2026-29013—22.0%
——7——CVE-2025-574898.1 HIG22.0%
——7Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.66dCVE-2019-0353—22.0%
——7——CVE-2026-32161—22.0%
——7——CVE-2026-671996.5 MED22.0%
——7Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration count in an expression column evaluated once per table row, causing the Tornado IOLoop to block without any iteration cap, deadline, or cancellation check, rendering the server unresponsive to all connected clients.35dCVE-2023-38017—22.0%
——7——CVE-2026-34069—22.0%
——7——CVE-2020-13467—22.0%
——7——CVE-2025-30295—22.0%
——7——CVE-2024-32048—22.0%
——7——CVE-2026-596526.5 MED22.0%
——7In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.7dCVE-2017-18803—22.0%
——7——CVE-2024-20368—22.0%
——7——CVE-2026-33555—22.0%
——7——CVE-2022-41281—21.9%
——7——CVE-2024-5890—22.0%
——7——CVE-2024-6254—22.0%
——7——CVE-2024-51890—22.0%
——7——CVE-2021-3461—22.0%
——7——CVE-2024-51889—22.0%
——7——CVE-2026-470854.0 MED22.0%
——7An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)53dCVE-2026-55188—22.0%
——7——CVE-2026-592133.5 LOW22.0%
——7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ollama.py passed a lambda to aiocache key instead of key_builder, causing permission-filtered per-user model lists to share a static cache entry and exposing one user’s model list to another caller during the TTL window. This issue is fixed in version 0.10.0.60d