Vulnerabilities exploitable today
359,665in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,517
- High11,189
- Medium7,120
- Low649
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-40694—11.0%
——3——CVE-2025-59986—11.0%
——3——CVE-2026-44352—11.0%
——3——CVE-2024-36509—11.0%
——3——CVE-2024-47753—11.0%
——3——CVE-2025-59998—11.0%
——3——CVE-2020-10066—11.0%
——3——CVE-2022-50005—11.0%
——3——CVE-2025-59992—11.0%
——3——CVE-2026-1337—11.0%
——3——CVE-2025-60001—11.0%
——3——CVE-2021-47790—11.0%
——3——CVE-2025-60009—11.0%
——3——CVE-2016-2059—11.0%
——3——CVE-2025-15145—11.0%
——3——CVE-2026-47382—11.0%
——3——CVE-2026-42744—11.0%
——3——CVE-2021-34400—11.0%
——3——CVE-2019-25314—11.0%
——3——CVE-2026-8990—11.0%
——3——CVE-2026-32736—11.0%
——3——CVE-2025-59994—11.0%
——3——CVE-2025-43241—11.0%
——3——CVE-2026-582115.4 MED11.0%
——3NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when the first client operation was not CONNECT, bypassing user-level connection restrictions such as allowed_connection_types or proxy_required that normal authentication would apply. This issue is fixed in versions 2.14.3 and 2.12.12.36dCVE-2025-55203—11.0%
——3——CVE-2026-45042—11.0%
——3——CVE-2026-18028—11.0%
——3The "quick setup" view presented to users after they first create an
event allows to set up the most critical parts of an event in just a few
clicks. This view did not properly check that the user has permission
to change configuration for the given event. An attacker could use a
well-timed request to create products, quotas, set bank transfer
configuration, or connect a stripe account to an event they do not have
access to.15dCVE-2026-40867—11.0%
——3——CVE-2018-9867—11.0%
——3——CVE-2022-48706—11.0%
——3——CVE-2026-42950—11.0%
——3——CVE-2025-61702.5 LOW11.0%
——3A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.4dCVE-2023-38612—11.0%
——3——CVE-2025-59988—11.0%
——3——CVE-2026-23625—11.0%
——3——CVE-2025-20022—11.0%
——3——CVE-2025-43818—11.0%
——3——CVE-2026-15227—11.0%
——3Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.14dCVE-2024-46784—11.0%
——3——CVE-2026-4295—11.0%
——3——