Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,357
- Medium5,357
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2010-3321—17.8%
——5——CVE-2025-43749—17.8%
——5——CVE-2025-32993—17.8%
——5——CVE-2026-655839.1 CRI17.8%
——5Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.26dCVE-2026-39937—17.8%
——5Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.42dCVE-2025-26867—17.8%
——5——CVE-2024-46677—17.8%
——5——CVE-2022-20762—17.8%
——5——CVE-2025-7032—17.8%
——5——CVE-2025-4594—17.8%
——5——CVE-2025-21544—17.8%
——5——CVE-2026-546098.6 HIG17.8%
——5QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No fixed version is available as of this review.33dCVE-2025-26888—17.8%
——5——CVE-2021-33060—17.8%
——5——CVE-2024-9169—17.8%
——5——CVE-2026-40881—17.8%
——5——CVE-2009-0875—17.8%
——5——CVE-2024-4942—17.8%
——5——CVE-2025-1277—17.8%
——5——CVE-2021-44463—17.8%
——5——CVE-2024-35283—17.8%
——5——CVE-2024-57055—17.8%
——5——CVE-2026-24813—17.8%
——5——CVE-2025-68949—17.8%
——5——CVE-2026-27981—17.8%
——5——CVE-2026-24798—17.8%
——5——CVE-2024-37239—17.8%
——5——CVE-2022-49223—17.8%
——5——CVE-2025-55006—17.8%
——5——CVE-2021-0004—17.8%
——5——CVE-2024-6225—17.8%
——5——CVE-2026-0902—17.8%
——5——CVE-2025-41076—17.8%
——5——CVE-2024-43300—17.8%
——5——CVE-2022-38956—17.8%
——5——CVE-2020-10774—17.8%
——5——CVE-2026-680918.8 HIG17.8%
——5In the Linux kernel, the following vulnerability has been resolved:
HID: wacom: stop hardware after post-start probe failures
wacom_parse_and_register() starts HID hardware before registering inputs
and initializing pad LEDs/remotes. Those later steps can fail, but their
error paths currently release Wacom resources without stopping the HID
hardware.
Route post-hid_hw_start() failures through hid_hw_stop() before
releasing driver resources.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.16dCVE-2024-37429—17.8%
——5——CVE-2021-21264—17.8%
——5——CVE-2025-0321—17.8%
——5——