Vulnerabilities exploitable today
364,333in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,674
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,320
- High9,833
- Medium4,881
- Low459
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-58820—13.4%
——4——CVE-2019-25384—13.4%
——4——CVE-2026-36923—13.4%
——4——CVE-2025-40003—13.4%
——4——CVE-2026-46007.4 HIG13.4%
——4Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certificates that X509.verifySignature() accepts by supplying malicious domain parameters such as g=1, y=1, and a fixed r=1, which make the verification equation true for any hash.7dCVE-2024-26985—13.4%
——4——CVE-2025-58256—13.4%
——4——CVE-2025-49318—13.4%
——4——CVE-2024-53707—13.4%
——4——CVE-2026-46538—13.4%
——4——CVE-2026-36919—13.4%
——4——CVE-2024-47158—13.4%
——4——CVE-2025-60070—13.4%
——4——CVE-2025-30941—13.4%
——4——CVE-2025-57980—13.4%
——4——CVE-2025-57998—13.4%
——4——CVE-2024-34639—13.4%
——4——CVE-2025-28989—13.4%
——4——CVE-2025-58810—13.4%
——4——CVE-2026-712398.1 HIG13.4%
——4DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content directly into a Template call; email_creators.py passes eml_message.subject directly as a template string to Template; and helpers.py contains the same f-string interpolation pattern.14dCVE-2025-53581—13.4%
——4——CVE-2026-36920—13.4%
——4——CVE-2025-54628—13.4%
——4——CVE-2024-2741—13.4%
——4——CVE-2025-58825—13.4%
——4——CVE-2025-49053—13.4%
——4——CVE-2025-48360—13.4%
——4——CVE-2025-48358—13.4%
——4——CVE-2025-30977—13.4%
——4——CVE-2025-49322—13.4%
——4——CVE-2026-149968.2 HIG13.4%
——4IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.19dCVE-2025-58245—13.4%
——4——CVE-2023-27908—13.4%
——4——CVE-2026-409856.4 MED13.4%
——4Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Affected versions:
Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.32dCVE-2025-58596—13.4%
——4——CVE-2024-1231—13.4%
——4——CVE-2025-30625—13.4%
——4——CVE-2024-35985—13.4%
——4——CVE-2025-57979—13.4%
——4——CVE-2021-47141—13.4%
——4——