Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,324
- High9,535
- Medium5,387
- Low522
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-30419—16.0%
——5——CVE-2025-41008—16.0%
——5——CVE-2024-44139—16.0%
——5——CVE-2026-194486.5 MED16.0%
——5IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service.4dCVE-2026-62857—16.0%
——5Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2.22dCVE-2025-7601—16.0%
——5——CVE-2025-12328—16.0%
——5——CVE-2024-31889—16.0%
——5——CVE-2026-2893—16.0%
——5——CVE-2025-6340—16.0%
——5——CVE-2019-25436—16.0%
——5——CVE-2024-29214—16.0%
——5——CVE-2021-22887—16.0%
——5——CVE-2024-39378—16.0%
——5——CVE-2025-13908—16.0%
——5——CVE-2025-63039—16.0%
——5——CVE-2026-32766—16.0%
——5——CVE-2023-32464—16.0%
——5——CVE-2023-49744—16.0%
——5——CVE-2025-5167—16.0%
——5——CVE-2025-62740—16.0%
——5——CVE-2025-66155—16.0%
——5——CVE-2025-66130—16.0%
——5——CVE-2025-68572—16.0%
——5——CVE-2025-66156—16.0%
——5——CVE-2025-12471—16.0%
——5——CVE-2020-22916—16.0%
——5——CVE-2025-5166—16.0%
——5——CVE-2026-40570—16.0%
——5——CVE-2025-67570—16.0%
——5——CVE-2023-34373—16.0%
——5——CVE-2025-68571—16.0%
——5——CVE-2026-308028.2 HIG16.0%
——5Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0, from 2.4.5 before 2.4.*.52dCVE-2025-69010—16.0%
——5——CVE-2023-48744—16.0%
——5——CVE-2025-68575—16.0%
——5——CVE-2022-31237—16.0%
——5——CVE-2025-62925—16.0%
——5——CVE-2025-5168—16.0%
——5——CVE-2025-66157—16.0%
——5——