Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,309
- High9,895
- Medium4,852
- Low455
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-66568—14.6%
——4——CVE-2021-33106—14.6%
——4——CVE-2017-20219—14.6%
——4——CVE-2024-41720—14.6%
——4——CVE-2024-26622—14.6%
——4——CVE-2025-23353—14.6%
——4——CVE-2022-42260—14.6%
——4——CVE-2024-2204—14.6%
——4——CVE-2025-8062—14.6%
——4——CVE-2026-8406—14.6%
——4——CVE-2026-50194—14.6%
——4——CVE-2025-24388—14.6%
——4——CVE-2026-52692—14.6%
——4——CVE-2026-502058.2 HIG14.6%
——4System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.36dCVE-2025-54393—14.6%
——4——CVE-2026-59233—14.6%
——4Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check before synchronizing the submitted permissions to the specified role.17dCVE-2024-23272—14.6%
——4——CVE-2024-21832—14.6%
——4——CVE-2025-22631—14.6%
——4——CVE-2025-64115—14.6%
——4——CVE-2026-124826.5 MED14.6%
——4A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.21dCVE-2024-26989—14.6%
——4——CVE-2025-58091—14.6%
——4——CVE-2026-179756.5 MED14.6%
——4Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)24dCVE-2025-700706.5 MED14.6%
——4An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()54dCVE-2023-23541—14.6%
——4——CVE-2024-46809—14.6%
——4——CVE-2023-23502—14.6%
——4——CVE-2025-46852—14.6%
——4——CVE-2025-46932—14.6%
——4——CVE-2026-138396.5 MED14.6%
——4Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)56dCVE-2026-7233—14.6%
——4——CVE-2025-58089—14.6%
——4——CVE-2024-7784—14.6%
——4——CVE-2025-22873—14.6%
——4——CVE-2025-58092—14.6%
——4——CVE-2025-14467—14.6%
——4——CVE-2026-624465.3 MED14.6%
——4Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).3dCVE-2025-5281—14.6%
——4——CVE-2026-145649.0 CRI14.6%
——4Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data.
This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.10d