Vulnerabilities exploitable today
367,851in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,393
- High9,631
- Medium5,587
- Low548
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-46827—18.6%
——6——CVE-2026-35504—18.6%
——6——CVE-2024-6126—18.6%
——6——CVE-2025-2023—18.6%
——6——CVE-2026-28254—18.6%
——6——CVE-2025-25585—18.6%
——6——CVE-2024-38318—18.6%
——6——CVE-2024-27885—18.6%
——6——CVE-2025-2015—18.6%
——6——CVE-2026-354017.5 HIG18.6%
——6Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource exhaustion. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.39dCVE-2025-58427—18.6%
——6——CVE-2026-22882—18.6%
——6——CVE-2025-64733—18.6%
——6——CVE-2024-11929—18.6%
——6——CVE-2025-52264—18.6%
——6——CVE-2026-42467—18.6%
——6——CVE-2026-0562—18.6%
——6——CVE-2025-64735—18.6%
——6——CVE-2025-23056—18.6%
——6——CVE-2025-2021—18.6%
——6——CVE-2004-2657—18.6%
——6——CVE-2025-2016—18.6%
——6——CVE-2024-8644—18.6%
——6——CVE-2025-54711—18.6%
——6——CVE-2025-62158—18.6%
——6——CVE-2026-30833—18.6%
——6——CVE-2025-43505—18.6%
——6——CVE-2024-8012—18.6%
——6——CVE-2025-5494—18.6%
——6——CVE-2026-584325.9 MED18.6%
——6Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea7dCVE-2025-53570—18.6%
——6——CVE-2025-14373—18.6%
——6——CVE-2025-66617—18.6%
——6——CVE-2026-29954—18.6%
——6——CVE-2024-51773—18.6%
——6——CVE-2024-54451—18.6%
——6——CVE-2025-41116—18.6%
——6——CVE-2026-21885—18.6%
——6——CVE-2025-53195—18.6%
——6——CVE-2024-45644—18.6%
——6——