Vulnerabilities exploitable today
356,708in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,545
- High10,617
- Medium6,752
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-53050—8.4%
——3——CVE-2022-49586—8.4%
——3——CVE-2025-7648—8.4%
——3——CVE-2025-6061—8.4%
——3——CVE-2019-9245—8.4%
——3——CVE-2023-53113—8.4%
——3——CVE-2025-33219—8.4%
——3——CVE-2025-33218—8.4%
——3——CVE-2025-47708—8.4%
——3——CVE-2025-6676—8.4%
——3——CVE-2026-113916.3 MED8.4%
——3Tanium addressed a SQL injection vulnerability in Patch.9dCVE-2022-49587—8.4%
——3——CVE-2023-7241—8.4%
——3——CVE-2026-92493.1 LOW8.4%
——3Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request.
This issue affects :
* Devolutions Server 2026.1.6.0 through 2026.1.16.0
* Devolutions Server 2025.3.20.0 and earlier17dCVE-2024-35495—8.4%
——3——CVE-2021-33081—8.4%
——3——CVE-2026-13030—8.4%
——3——CVE-2025-49737—8.4%
——3——CVE-2026-13023—8.4%
——3——CVE-2022-49854—8.4%
——3——CVE-2025-6674—8.4%
——3——CVE-2023-21445—8.4%
——3——CVE-2025-31212—8.4%
——3——CVE-2025-43484—8.4%
——3——CVE-2024-50118—8.4%
——3——CVE-2026-33569—8.4%
——3——CVE-2025-40946—8.4%
——3——CVE-2023-52935—8.4%
——3——CVE-2025-47701—8.4%
——3——CVE-2023-25777—8.4%
——3——CVE-2025-68516—8.3%
——3——CVE-2025-66053—8.4%
——3——CVE-2024-12634—8.4%
——3——CVE-2025-36180—8.4%
——3——CVE-2025-67551—8.4%
——3——CVE-2025-604647.8 HIG8.4%
——3A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 TS file.39dCVE-2025-67536—8.4%
——3——CVE-2025-9906—8.4%
——3——CVE-2024-56712—8.4%
——3——CVE-2026-100524.1 MED8.4%
——3A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.19d