Vulnerabilities exploitable today
358,921in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,708
- High11,664
- Medium7,446
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-53699—10.0%
——3——CVE-2019-1985—10.0%
——3——CVE-2014-8518—10.0%
——3——CVE-2025-21768—10.0%
——3——CVE-2022-50580—10.0%
——3——CVE-2025-14958—10.0%
——3——CVE-2024-37412—10.0%
——3——CVE-2026-0559—10.0%
——3——CVE-2022-49304—10.0%
——3——CVE-2019-25390—10.0%
——3——CVE-2026-11852—10.0%
——3——CVE-2026-45134—10.0%
——3——CVE-2026-41321—10.0%
——3——CVE-2025-7961—10.0%
——3——CVE-2025-43877—10.0%
——3——CVE-2025-65858—10.0%
——3——CVE-2025-58962—10.0%
——3——CVE-2026-585277.8 HIG10.0%
——3Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.22dCVE-2022-50556—10.0%
——3——CVE-2023-53700—10.0%
——3——CVE-2025-43379—10.0%
——3——CVE-2024-12975—10.0%
——3——CVE-2025-635797.5 HIG10.0%
——3Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects Kyocera Command Center RX TASKalfa 2552ci, TASKalfa 3252ci, TASKalfa 2553ci, TASKalfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TASKalfa 5052ci, TASKalfa 6052ci, TASKalfa 7052ci, TASKalfa 8052ci, TASKalfa 7353ci, TASKalfa 8353ci, TASKalfa 2554ci, TASKalfa 3254ci, TASKalfa 505.34dCVE-2026-503977.0 HIG10.0%
——3Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.22dCVE-2025-6633—10.0%
——3——CVE-2025-43551—10.0%
——3——CVE-2026-1300—10.0%
——3——CVE-2022-35415—10.0%
——3——CVE-2026-13027—10.0%
——3——CVE-2025-66081—10.0%
——3——CVE-2025-65956—10.0%
——3——CVE-2024-56435—10.0%
——3——CVE-2026-3074—10.0%
——3——CVE-2024-12280—10.0%
——3——CVE-2026-6439—10.0%
——3——CVE-2026-4165—10.0%
——3——CVE-2022-50560—10.0%
——3——CVE-2023-51777—10.0%
——3——CVE-2026-121356.4 MED10.0%
——3The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.43dCVE-2024-22105—10.0%
——3——