Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-47051—21.8%
——7——CVE-2025-47050—21.8%
——7——CVE-2023-30406—21.8%
——7——CVE-2025-11438—21.8%
——7——CVE-2024-37428—21.8%
——7——CVE-2025-53021—21.8%
——7——CVE-2026-19801—21.8%
——7——CVE-2025-47042—21.8%
——7——CVE-2023-30410—21.8%
——7——CVE-2025-23259—21.8%
——7——CVE-2023-3427—21.8%
——7——CVE-2024-43951—21.8%
——7——CVE-2024-39668—21.8%
——7——CVE-2024-447936.1 MED21.8%
——7A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.66dCVE-2025-47011—21.8%
——7——CVE-2022-28714—21.8%
——7——CVE-2024-21609—21.8%
——7——CVE-2025-47003—21.8%
——7——CVE-2026-40827—21.8%
——7——CVE-2023-30414—21.8%
——7——CVE-2025-47057—21.8%
——7——CVE-2023-30910—21.8%
——7——CVE-2025-712177.8 HIG21.8%
——7An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).47dCVE-2023-2286—21.8%
——7——CVE-2026-57533—21.8%
——7——CVE-2025-27216—21.8%
——7——CVE-2024-39583—21.8%
——7——CVE-2024-447946.1 MED21.8%
——7A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.66dCVE-2026-40828—21.8%
——7——CVE-2025-47025—21.8%
——7——CVE-2024-447956.1 MED21.8%
——7A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.66dCVE-2023-2563—21.8%
——7——CVE-2018-6592—21.8%
——7——CVE-2024-21605—21.8%
——7——CVE-2021-25507—21.8%
——7——CVE-2026-426796.5 MED21.8%
——7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal.
This issue affects Classified Listing: from n/a through 5.3.8.49dCVE-2026-704896.5 MED21.8%
——7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules at a fixed date of 2000-01-01 and then walked forward one interval at a time to find the next run. A single FREQ=MINUTELY rule enumerates roughly a quarter-century of occurrences synchronously on the event loop that also serves scheduler, HTTP, and WebSocket traffic, and the scheduler recomputes the next run for every claimed row on each poll. This causes availability impact for every other user of the instance. This issue is fixed in 0.11.0.34dCVE-2025-46987—21.8%
——7——CVE-2022-3266—21.8%
——7——CVE-2025-47012—21.8%
——7——