Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,394
- High10,137
- Medium5,050
- Low465
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-23461—13.6%
——4——CVE-2025-23489—13.6%
——4——CVE-2026-24050—13.6%
——4——CVE-2025-54232—13.6%
——4——CVE-2026-57646—13.6%
——4——CVE-2024-56603—13.6%
——4——CVE-2025-12281—13.6%
——4——CVE-2025-12280—13.6%
——4——CVE-2024-47082—13.6%
——4——CVE-2025-23711—13.6%
——4——CVE-2021-41199—13.6%
——4——CVE-2026-13537—13.6%
——4——CVE-2026-585895.4 MED13.6%
——4Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.42dCVE-2024-31684—13.6%
——4——CVE-2021-46965—13.6%
——4——CVE-2024-27260—13.6%
——4——CVE-2026-39321—13.6%
——4——CVE-2024-42080—13.6%
——4——CVE-2025-54230—13.6%
——4——CVE-2015-7335—13.6%
——4——CVE-2025-54229—13.6%
——4——CVE-2026-654785.4 MED13.6%
——4Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.33dCVE-2026-39463—13.6%
——4——CVE-2026-153287.4 HIG13.6%
——4IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.20dCVE-2026-25533—13.6%
——4——CVE-2023-43578—13.6%
——4——CVE-2026-162164.3 MED13.6%
——4A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.35dCVE-2023-43577—13.6%
——4——CVE-2025-9540—13.6%
——4——CVE-2026-574136.4 MED13.6%
——4Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects Instant Image Generator: from n/a through <= 2.1.4.43dCVE-2024-45687—13.6%
——4——CVE-2024-44129—13.6%
——4——CVE-2026-43993—13.6%
——4——CVE-2025-12726—13.6%
——4——CVE-2025-2230—13.6%
——4——CVE-2023-43567—13.6%
——4——CVE-2025-9490—13.6%
——4——CVE-2023-35894—13.6%
——4——CVE-2026-762058.1 HIG13.6%
——4phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft a payload with a dangling backslash to escape the closing quote and inject arbitrary SQL commands to read sensitive database information.4dCVE-2025-62013—13.6%
——4——