Vulnerabilities exploitable today
367,144in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,256
- High9,258
- Medium5,266
- Low507
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-20010—17.0%
——5——CVE-2024-45303—17.0%
——5——CVE-2020-15495—17.0%
——5——CVE-2024-51953—17.0%
——5——CVE-2024-45326—17.0%
——5——CVE-2025-59983—17.0%
——5——CVE-2024-12020—17.0%
——5——CVE-2012-2373—17.0%
——5——CVE-2026-164057.5 HIG17.0%
——5Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.40dCVE-2024-51947—17.0%
——5——CVE-2024-45776—17.0%
——5——CVE-2024-39594—17.0%
——5——CVE-2024-38344—17.0%
——5——CVE-2021-26316—17.0%
——5——CVE-2022-49241—17.0%
——5——CVE-2024-35664—17.0%
——5——CVE-2024-54012—17.0%
——5——CVE-2024-30799—17.0%
——5——CVE-2026-673116.8 MED17.0%
——5Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an external server that returns a redirect to internal IP addresses, bypassing blacklist protection to access cloud metadata endpoints and internal services.28dCVE-2022-49329—17.0%
——5——CVE-2021-47893—17.0%
——5——CVE-2022-49229—17.0%
——5——CVE-2024-34685—17.0%
——5——CVE-2026-169887.5 HIG17.0%
——5The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.5dCVE-2024-51952—17.0%
——5——CVE-2025-14033—17.0%
——5——CVE-2024-51944—17.0%
——5——CVE-2022-49642—17.0%
——5——CVE-2026-749547.5 HIG17.0%
——5Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.12dCVE-2024-54372—17.0%
——5——CVE-2023-47825—17.0%
——5——CVE-2023-49816—17.0%
——5——CVE-2022-3025—17.0%
——5——CVE-2024-5888—17.0%
——5——CVE-2023-47787—17.0%
——5——CVE-2026-8494—17.0%
——5——CVE-2022-49613—17.0%
——5——CVE-2022-49195—17.0%
——5——CVE-2022-49262—17.0%
——5——CVE-2020-37174—17.0%
——5——