Vulnerabilities exploitable today
359,665in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,517
- High11,189
- Medium7,120
- Low649
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-37102—11.0%
——3——CVE-2025-32964—11.0%
——3——CVE-2025-59990—11.0%
——3——CVE-2026-5798—11.0%
——3——CVE-2026-4063—11.0%
——3——CVE-2022-50887—11.0%
——3——CVE-2026-4764—11.0%
——3——CVE-2026-11369—11.0%
——3——CVE-2025-59985—11.0%
——3——CVE-2020-11146—11.0%
——3——CVE-2022-48841—11.0%
——3——CVE-2026-331047.0 HIG11.0%
——3Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.21dCVE-2025-40693—11.0%
——3——CVE-2026-21299—11.0%
——3——CVE-2022-48888—11.0%
——3——CVE-2025-60000—11.0%
——3——CVE-2025-27065—11.0%
——3——CVE-2026-193523.1 LOW11.0%
——3A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: "I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug." The CVSS vector reflects the high level of pre-requisites.2dCVE-2026-60125—11.0%
——3MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not enforce the per-organisation module restriction checked by getEnabledModules(). As a result, an authenticated user from an organisation that was not allowed to use a module restricted via Plugin.Import_<module>_restrict could still invoke that import module directly if they knew its name.
This could allow unauthorised access to restricted import-module functionality and, depending on the module and the user’s event permissions, may allow unauthorised import or modification of event data through a module that should have been unavailable to the user’s organisation.36dCVE-2026-53911—11.0%
——3——CVE-2026-117148.5 HIG11.0%
——3IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.8dCVE-2021-34399—11.0%
——3——CVE-2026-54362—11.0%
——3——CVE-2025-41768—11.0%
——3——CVE-2025-43800—11.0%
——3——CVE-2025-40696—11.0%
——3——CVE-2023-24475—11.0%
——3——CVE-2024-5029—11.0%
——3——CVE-2026-45412—11.0%
——3MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URLs in work_flow_template.downloadUrl which are fetched server-side without any URL validation or internal IP filtering. This vulnerability is fixed in 2.9.1.23dCVE-2025-61781—11.0%
——3——CVE-2026-45371—11.0%
——3——CVE-2021-1105—11.0%
——3——CVE-2026-45297—11.0%
——3——CVE-2023-2919—11.0%
——3——CVE-2025-57876—11.0%
——3——CVE-2025-49112—11.0%
——3——CVE-2024-47501—11.0%
——3——CVE-2022-23523—11.0%
——3——CVE-2022-49776—11.0%
——3——CVE-2025-54243—11.0%
——3——