Vulnerabilities exploitable today
358,987in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,465
- High10,986
- Medium6,932
- Low650
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-24309—10.7%
——3——CVE-2024-41254—10.7%
——3——CVE-2022-50971—10.7%
——3——CVE-2022-0353—10.7%
——3——CVE-2025-67558—10.7%
——3——CVE-2023-7025—10.7%
——3——CVE-2025-12017—10.7%
——3——CVE-2022-50568—10.7%
——3——CVE-2025-7227—10.7%
——3——CVE-2025-69674—10.7%
——3——CVE-2022-48884—10.7%
——3——CVE-2026-57636—10.7%
——3——CVE-2020-5315—10.7%
——3——CVE-2025-55012—10.7%
——3——CVE-2026-25022—10.7%
——3——CVE-2024-53287—10.7%
——3——CVE-2020-5969—10.7%
——3——CVE-2026-482485.9 MED10.7%
——3Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests issued during the login/authentication flow. An attacker positioned on the network path between the server and the remote endpoint can present a forged certificate to intercept, monitor, or modify the request and response, including any API keys or session-bearing data in transit.22dCVE-2025-67557—10.7%
——3——CVE-2026-5243—10.7%
——3——CVE-2023-53704—10.7%
——3——CVE-2025-67554—10.7%
——3——CVE-2026-111666.8 MED10.7%
——3Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)22dCVE-2026-563365.3 MED10.7%
——3Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO provider identifiers, enabling reconnaissance against Capgo tenants.31dCVE-2025-7246—10.7%
——3——CVE-2023-31423—10.7%
——3——CVE-2023-52895—10.7%
——3——CVE-2025-7229—10.7%
——3——CVE-2025-7243—10.7%
——3——CVE-2026-57662—10.7%
——3——CVE-2026-614308.5 HIG10.7%
——3PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.30dCVE-2022-31251—10.7%
——3——CVE-2026-78814.3 MED10.7%
——3Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express form submissions. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani for reporting.22dCVE-2023-40071—10.7%
——3——CVE-2026-3665—10.7%
——3——CVE-2026-0977—10.7%
——3——CVE-2026-34351—10.7%
——3——CVE-2022-49702—10.7%
——3——CVE-2025-68422—10.7%
——3——CVE-2022-49871—10.7%
——3——