Vulnerabilities exploitable today
356,684in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,537
- High10,637
- Medium6,742
- Low667
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-9713—8.3%
——2——CVE-2026-25329—8.3%
——2——CVE-2026-41046—8.3%
——2——CVE-2026-25313—8.3%
——2——CVE-2025-24258—8.3%
——2——CVE-2022-1038—8.3%
——2——CVE-2025-48329—8.3%
——2——CVE-2025-4002—8.3%
——2——CVE-2026-25363—8.3%
——2——CVE-2026-396534.3 MED8.3%
——2Missing Authorization vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Conferencing with Zoom: from n/a through <= 4.6.6.15dCVE-2025-4003—8.3%
——2——CVE-2025-43523—8.3%
——2——CVE-2025-24185—8.3%
——2——CVE-2026-24543—8.3%
——2——CVE-2026-22481—8.3%
——2——CVE-2025-54055—8.3%
——2——CVE-2026-50200—8.3%
——2——CVE-2023-22883—8.3%
——2——CVE-2026-24522—8.3%
——2——CVE-2026-273924.3 MED8.3%
——2Contributor Broken Access Control in uListing <= 2.2.0 versions.17dCVE-2026-24579—8.3%
——2——CVE-2026-25394—8.3%
——2——CVE-2024-43762—8.3%
——2——CVE-2026-24571—8.3%
——2——CVE-2026-28080—8.3%
——2——CVE-2025-21538—8.3%
——2——CVE-2019-2192—8.3%
——2——CVE-2025-43398—8.3%
——2——CVE-2026-2258—8.3%
——2——CVE-2023-53346—8.3%
——2——CVE-2022-50353—8.3%
——2——CVE-2026-24985—8.3%
——2——CVE-2026-69248—8.3%
——2cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.4dCVE-2023-53344—8.3%
——2——CVE-2025-53579—8.3%
——2——CVE-2023-29113—8.3%
——2——CVE-2022-50030—8.3%
——2——CVE-2025-43836—8.3%
——2——CVE-2026-22468—8.3%
——2——CVE-2026-24580—8.3%
——2——