Vulnerabilities exploitable today
364,333in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,674
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,320
- High9,833
- Medium4,881
- Low459
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-40912—13.5%
——4——CVE-2024-44647—13.5%
——4——CVE-2021-46928—13.5%
——4——CVE-2024-26662—13.5%
——4——CVE-2026-53857—13.5%
——4——CVE-2024-26803—13.5%
——4——CVE-2026-105475.9 MED13.5%
——4IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service.18dCVE-2026-165815.3 MED13.5%
——4In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.25dCVE-2024-41065—13.5%
——4——CVE-2022-24286—13.5%
——4——CVE-2024-36917—13.5%
——4——CVE-2021-472105.5 MED13.4%
——4In the Linux kernel, the following vulnerability has been resolved:
usb: typec: tipd: Remove WARN_ON in tps6598x_block_read
Calling tps6598x_block_read with a higher than allowed len can be
handled by just returning an error. There's no need to crash systems
with panic-on-warn enabled.13dCVE-2025-58665—13.4%
——4——CVE-2025-58661—13.4%
——4——CVE-2019-25380—13.4%
——4——CVE-2019-25449—13.4%
——4——CVE-2025-48323—13.4%
——4——CVE-2020-10052—13.4%
——4——CVE-2025-49318—13.4%
——4——CVE-2025-58820—13.4%
——4——CVE-2025-49048—13.4%
——4——CVE-2025-48324—13.4%
——4——CVE-2025-58647—13.4%
——4——CVE-2025-30875—13.4%
——4——CVE-2024-43911—13.4%
——4——CVE-2026-20711—13.4%
——4——CVE-2024-35943—13.4%
——4——CVE-2024-35800—13.4%
——4——CVE-2025-58646—13.4%
——4——CVE-2025-27461—13.4%
——4——CVE-2025-58256—13.4%
——4——CVE-2019-25384—13.4%
——4——CVE-2025-40003—13.4%
——4——CVE-2026-36923—13.4%
——4——CVE-2024-26985—13.4%
——4——CVE-2026-46007.4 HIG13.4%
——4Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certificates that X509.verifySignature() accepts by supplying malicious domain parameters such as g=1, y=1, and a fixed r=1, which make the verification equation true for any hash.7dCVE-2024-53707—13.4%
——4——CVE-2021-47150—13.4%
——4——CVE-2025-60068—13.4%
——4——CVE-2026-176594.2 MED13.4%
——4Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)19d