Vulnerabilities exploitable today
359,691in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,519
- High11,197
- Medium7,130
- Low645
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-53982—11.2%
——3——CVE-2025-54006—11.2%
——3——CVE-2025-41077—11.2%
——3——CVE-2022-23087—11.2%
——3——CVE-2026-23035—11.2%
——3——CVE-2026-47170—11.2%
——3——CVE-2024-24488—11.2%
——3——CVE-2026-36759—11.2%
——3——CVE-2023-42848—11.2%
——3——CVE-2025-31997—11.2%
——3——CVE-2026-33014—11.2%
——3——CVE-2024-4382—11.2%
——3——CVE-2025-41078—11.2%
——3——CVE-2025-69024—11.2%
——3——CVE-2026-6709—11.2%
——3——CVE-2025-48295—11.2%
——3——CVE-2025-48946—11.2%
——3——CVE-2026-712086.5 MED11.2%
——3KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery.ServerVersion against the CRD-specified Kubernetes API endpoint, which is parsed only for URL syntax (url.Parse) with no allow/deny-list for loopback, RFC1918 private ranges, link-local, or cloud-metadata addresses (e.g. 169.254.169.254).5dCVE-2025-53989—11.2%
——3——CVE-2024-22038—11.2%
——3——CVE-2025-59567—11.2%
——3——CVE-2026-659256.5 MED11.2%
——3A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.16dCVE-2026-538238.1 HIG11.2%
——3OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other identities.23dCVE-2025-47598—11.2%
——3——CVE-2024-9017—11.2%
——3——CVE-2025-46233—11.2%
——3——CVE-2025-57877—11.2%
——3——CVE-2025-57874—11.2%
——3——CVE-2022-48895—11.2%
——3——CVE-2025-53991—11.2%
——3——CVE-2026-41905—11.2%
——3——CVE-2024-46672—11.2%
——3——CVE-2021-0256—11.2%
——3——CVE-2022-50819—11.2%
——3——CVE-2026-44547—11.2%
——3——CVE-2026-3293—11.2%
——3——CVE-2026-149326.5 MED11.2%
——3In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.9dCVE-2025-30313—11.2%
——3——CVE-2026-465566.5 MED11.2%
——3FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metadata services. This is a blind SSRF with confirmed internal port scanning and internal API triggering capabilities. Version 2.2.1 patches the issue.23dCVE-2023-24518—11.2%
——3——