Vulnerabilities exploitable today
360,749in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,492
- High11,026
- Medium7,022
- Low631
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-20026—11.8%
——4——CVE-2025-21130—11.8%
——4——CVE-2015-8223—11.8%
——4——CVE-2024-47094—11.8%
——4——CVE-2019-14711—11.8%
——4——CVE-2020-3629—11.8%
——4——CVE-2026-6107—11.8%
——4——CVE-2024-44971—11.8%
——4——CVE-2025-27327—11.8%
——4——CVE-2021-41023—11.8%
——4——CVE-2026-24584—11.8%
——4——CVE-2018-19279—11.8%
——4——CVE-2023-22613—11.8%
——4——CVE-2025-1664—11.8%
——4——CVE-2026-1948—11.8%
——4——CVE-2021-1306—11.8%
——4——CVE-2024-43870—11.8%
——4——CVE-2024-1361—11.8%
——4——CVE-2015-7740—11.8%
——4——CVE-2024-9524—11.8%
——4——CVE-2026-31801—11.8%
——4——CVE-2024-43869—11.8%
——4——CVE-2025-27348—11.8%
——4——CVE-2026-499818.2 HIG11.8%
——4Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.26dCVE-2024-43875—11.8%
——4——CVE-2024-46699—11.8%
——4——CVE-2024-46973—11.8%
——4——CVE-2024-46600—11.8%
——4——CVE-2024-0660—11.8%
——4——CVE-2024-57931—11.8%
——4——CVE-2024-55412—11.8%
——4——CVE-2025-20898—11.8%
——4——CVE-2025-31218—11.8%
——4——CVE-2025-27331—11.8%
——4——CVE-2026-35202—11.8%
——4Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass their assigned limits for database allocations. This happens because the database locking mechanism used in the controllers is totally broken and doesn't actually lock anything. Version 1.12.3 patches the issue.25dCVE-2025-24267—11.8%
——4——CVE-2024-13962—11.8%
——4——CVE-2024-53143—11.8%
——4——CVE-2026-130734.3 MED11.8%
——4An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine selection inconsistency triggered by a specific combination of aggregation options.24dCVE-2024-10716—11.8%
——4——