Vulnerabilities exploitable today
368,587in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631
Distribution · last window
- Critical2,202
- High7,824
- Medium5,620
- Low550
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-22881—19.5%
——6——CVE-2026-50564—19.5%
——6——CVE-2026-3163—19.5%
——6——CVE-2025-658286.5 MED19.5%
——6An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which would result in a Denial of Service. These commands include: shutdown, restart, clear config. Clear config would disassociate the current device from its user and would require re-configuration to re-enable the device. As a result, the end user would be unable to receive updates from the Meatmeet base station which communicates with the cloud services until the device had been fixed or turned back on.61dCVE-2018-4428—19.5%
——6——CVE-2024-12444—19.5%
——6——CVE-2025-13414—19.5%
——6——CVE-2025-26938—19.5%
——6——CVE-2025-37101—19.4%
——6——CVE-2024-37545—19.4%
——6——CVE-2023-50481—19.4%
——6——CVE-2024-52975—19.4%
——6——CVE-2021-35231—19.4%
——6——CVE-2025-5699—19.4%
——6——CVE-2020-4951—19.4%
——6——CVE-2023-50570—19.4%
——6——CVE-2024-52491—19.4%
——6——CVE-2026-6415—19.4%
——6——CVE-2022-49644—19.4%
——6——CVE-2026-731227.7 HIG19.4%
——6A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm repositories. This could lead to significant information disclosure.8dCVE-2025-3121—19.4%
——6——CVE-2020-13353—19.4%
——6——CVE-2026-26964—19.4%
——6——CVE-2026-33356—19.4%
——6——CVE-2017-9676—19.4%
——6——CVE-2023-40406—19.4%
——6——CVE-2025-6977—19.4%
——6——CVE-2024-37562—19.4%
——6——CVE-2024-43137—19.4%
——6——CVE-2025-154373.5 LOW19.4%
——6A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 6.1.26 and 6.3 is able to mitigate this issue. The patch is named 264ac5b2be5b3c673ebd8cb862e673f5d300d9a7. The affected component should be upgraded.41dCVE-2022-49115—19.4%
——6——CVE-2026-691837.5 HIG19.4%
——6Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before the trust-proxy-derived req.ip value. An unauthenticated attacker can rotate either header to create a new bucket for each request, bypassing rootRateLimiter, badAuthRateLimiter, getKey(), and the getKeyWithUid() fallback used by public endpoints. This permits repeated POST /users/forgotPasswordEmail and verificationEmail requests, mail bombing registered users, consuming Firebase or SMTP quota, evading brute-force protection, and enabling resource exhaustion. Exploitability of cf-connecting-ip depends on deployment topology, but x-forwarded-for and direct-to-origin paths remain affected when those values are not overwritten by a trusted proxy. No fixed version is available as of this review.15dCVE-2026-33540—19.4%
——6——CVE-2024-52489—19.4%
——6——CVE-2025-15260—19.4%
——6——CVE-2025-68951—19.4%
——6——CVE-2023-43627—19.4%
——6——CVE-2025-21135—19.4%
——6——CVE-2025-15452—19.4%
——6——CVE-2025-62922—19.4%
——6——