Vulnerabilities exploitable today
354,825in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,569
- High9,189
- Medium7,426
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-68298—5.7%
——2——CVE-2023-20515—5.7%
——2——CVE-2018-9560—5.7%
——2——CVE-2025-2236—5.7%
——2——CVE-2020-0259—5.7%
——2——CVE-2025-67443—5.7%
——2——CVE-2025-68240—5.7%
——2——CVE-2022-4149—5.7%
——2——CVE-2025-48921—5.7%
——2——CVE-2024-56744—5.7%
——2——CVE-2017-17767—5.7%
——2——CVE-2022-27187—5.7%
——2——CVE-2025-68242—5.7%
——2——CVE-2025-26850—5.7%
——2——CVE-2017-15846—5.7%
——2——CVE-2025-23627—5.7%
——2——CVE-2025-68329—5.7%
——2——CVE-2025-1435—5.7%
——2——CVE-2026-92217.5 HIG5.7%
——2The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and the backend REST API. Attackers could potentially reverse the signature to recover the session ID. With the session ID exposed, an attacker could impersonate the legitimate user and issue authenticated API requests.32dCVE-2024-58095—5.7%
——2——CVE-2026-656976.1 MED5.7%
——2Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javascript: URI into the Top Pages dashboard by supplying a crafted hostname and pathname to the unauthenticated /collect endpoint. The parseHostname and parsePathname functions perform no URI scheme validation, allowing a javascript: hostname combined with a newline-prefixed pathname to be stored and later rendered as an anchor href in the authenticated dashboard without sanitization, enabling session hijacking and full account takeover when an operator clicks the poisoned entry.9dCVE-2017-17771—5.7%
——2——CVE-2023-52432—5.7%
——2——CVE-2025-38457—5.7%
——2——CVE-2025-68251—5.7%
——2——CVE-2026-20615—5.7%
——2——CVE-2026-654964.4 MED5.7%
——2Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.9dCVE-2026-10097—5.7%
——2——CVE-2024-4601—5.7%
——2——CVE-2024-58319—5.7%
——2——CVE-2026-22093—5.7%
——2The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and server. The traffic is weakly encrypted using RC4 with a hardcoded key, which allows an attacker to gain access to the communication. Part of this communication involves access codes to charging stations.
This issue affects EVbee Service: v1.4.101.00.19dCVE-2025-379777.8 HIG5.7%
——2In the Linux kernel, the following vulnerability has been resolved:
scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set
If dma-coherent property isn't set then descriptors are non-cacheable
and the iocc shareability bits should be disabled. Without this UFS can
end up in an incompatible configuration and suffer from random cache
related stability issues.3dCVE-2025-52458—5.7%
——2——CVE-2024-6299—5.7%
——2——CVE-2025-53277—5.7%
——2——CVE-2025-21550—5.7%
——2——CVE-2025-8884—5.7%
——2——CVE-2025-38371—5.7%
——2——CVE-2025-23640—5.7%
——2——CVE-2025-68300—5.7%
——2——