Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,360
- High9,604
- Medium5,458
- Low531
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-64557—15.5%
——5——CVE-2018-7989—15.5%
——5——CVE-2024-48702—15.5%
——5——CVE-2025-15154—15.5%
——5——CVE-2025-64572—15.5%
——5——CVE-2025-13132—15.5%
——5——CVE-2025-64556—15.5%
——5——CVE-2009-2094—15.5%
——5——CVE-2025-62722—15.5%
——5——CVE-2024-28238—15.5%
——5——CVE-2025-64609—15.5%
——5——CVE-2025-64598—15.5%
——5——CVE-2022-1697—15.5%
——5——CVE-2020-4631—15.5%
——5——CVE-2025-64789—15.5%
——5——CVE-2026-86614.8 MED15.5%
——5Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import) embedded in Markdown input. The initial fix in 4.0.0 disabled JavaScript but did not neutralize resource-loading vectors. Resolved in 4.0.2 by sanitizing HTML with an allowlist of tags, attributes, and URL schemes.36dCVE-2024-47368—15.5%
——5——CVE-2025-64592—15.5%
——5——CVE-2025-45754—15.5%
——5——CVE-2021-25398—15.5%
——5——CVE-2025-64558—15.5%
——5——CVE-2025-64591—15.5%
——5——CVE-2025-64808—15.5%
——5——CVE-2025-64583—15.5%
——5——CVE-2025-64615—15.5%
——5——CVE-2025-64791—15.5%
——5——CVE-2025-64790—15.5%
——5——CVE-2025-64745—15.5%
——5——CVE-2024-33401—15.5%
——5——CVE-2026-347707.0 HIG15.5%
——5Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retain dangling references. A subsequent session-change event (Windows) or system shutdown (macOS) dereferences freed memory, which may lead to a crash or memory corruption. All apps that access powerMonitor events (suspend, resume, lock-screen, etc.) are potentially affected. The issue is not directly renderer-controllable. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8.35dCVE-2025-64590—15.5%
——5——CVE-2024-13590—15.5%
——5——CVE-2024-45464—15.5%
——5——CVE-2024-51108—15.5%
——5——CVE-2025-64586—15.5%
——5——CVE-2024-3857—15.5%
——5——CVE-2025-64579—15.5%
——5——CVE-2021-25404—15.5%
——5——CVE-2025-64605—15.5%
——5——CVE-2025-64606—15.5%
——5——