Vulnerabilities exploitable today
369,220in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,169
- High7,791
- Medium5,692
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-37460—19.8%
——6——CVE-2025-52497—19.8%
——6——CVE-2026-0139—19.8%
——6——CVE-2023-50859—19.8%
——6——CVE-2026-32023—19.8%
——6——CVE-2026-44214—19.8%
——6——CVE-2026-4276—19.8%
——6——CVE-2025-57976—19.7%
——6——CVE-2017-1378—19.7%
——6——CVE-2024-13708—19.7%
——6——CVE-2025-52817—19.7%
——6——CVE-2020-3503—19.7%
——6——CVE-2025-538318.2 HIG19.7%
——6DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prior to version 10.15.3, attackers with access to the DrawIO app can leverage improper neutralization of input during web page generation to achieve stored XSS. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade DrawIO for ownCloud 10 to version 1.0.2 or later to receive a patch.61dCVE-2025-36625—19.7%
——6——CVE-2025-66553—19.7%
——6——CVE-2021-33436—19.7%
——6——CVE-2025-10048—19.7%
——6——CVE-2024-27158—19.7%
——6——CVE-2022-42947—19.7%
——6——CVE-2025-32228—19.7%
——6——CVE-2023-53820—19.7%
——6——CVE-2026-4739—19.7%
——6——CVE-2024-21670—19.7%
——6——CVE-2025-3809—19.7%
——6——CVE-2022-50659—19.7%
——6——CVE-2025-47585—19.7%
——6——CVE-2017-1201—19.7%
——6——CVE-2019-25713—19.7%
——6——CVE-2017-18450—19.7%
——6——CVE-2025-20385—19.7%
——6——CVE-2026-1898—19.7%
——6——CVE-2025-32056—19.7%
——6——CVE-2023-33760—19.7%
——6——CVE-2026-12822—19.7%
——6——CVE-2026-580516.5 MED19.7%
——6libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.67dCVE-2026-1720—19.7%
——6——CVE-2021-34577—19.7%
——6——CVE-2023-51390—19.7%
——6——CVE-2023-32240—19.7%
——6——CVE-2025-59814—19.7%
——6——