Vulnerabilities exploitable today
354,825in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,569
- High9,189
- Medium7,426
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-71304—5.7%
——2——CVE-2020-36991—5.7%
——2——CVE-2026-493254.6 MED5.7%
——2Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via a falling-edge voltage transition on a dedicated wire pair. The receiving ECU does not distinguish between an active shutdown pulse and an open-circuit / disconnected condition; interrupting the relevant wires leaves the motorcycle fully operable even though the WCM never validated the rider's PIN. Specific connector details have been withheld pending vendor remediation.11dCVE-2026-6530—5.7%
——2——CVE-2026-12781—5.7%
——2——CVE-2026-12782—5.7%
——2——CVE-2020-36984—5.7%
——2——CVE-2025-71305—5.7%
——2——CVE-2025-9036—5.7%
——2——CVE-2023-20601—5.7%
——2——CVE-2025-39808—5.7%
——2——CVE-2024-5166—5.7%
——2——CVE-2025-39676—5.7%
——2——CVE-2024-44210—5.7%
——2——CVE-2022-26124—5.7%
——2——CVE-2026-6870—5.7%
——2——CVE-2026-44637—5.6%
——2——CVE-2025-13939—5.6%
——2——CVE-2022-50032—5.6%
——2——CVE-2025-53600—5.6%
——2——CVE-2026-200747.4 HIG5.6%
——2A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly.
This vulnerability is due to insufficient input validation of ingress IS-IS packets. An attacker could exploit this vulnerability by sending crafted IS-IS packets to an affected device after forming an adjacency. A successful exploit could allow the attacker to cause the IS-IS process to restart unexpectedly, resulting in a temporary loss of connectivity to advertised networks and a denial of service (DoS) condition.
Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2-adjacent to the affected device and must have formed an adjacency. 24dCVE-2026-45965—5.6%
——2——CVE-2021-26315—5.6%
——2——CVE-2025-2274—5.6%
——2——CVE-2026-45848—5.6%
——2——CVE-2023-52586—5.6%
——2——CVE-2022-50141—5.6%
——2——CVE-2022-50143—5.6%
——2——CVE-2022-50161—5.6%
——2——CVE-2024-49313—5.6%
——2——CVE-2025-58486—5.6%
——2——CVE-2022-50124—5.6%
——2——CVE-2026-30896—5.6%
——2——CVE-2022-50160—5.6%
——2——CVE-2025-9341—5.6%
——2——CVE-2022-50123—5.6%
——2——CVE-2025-38040—5.6%
——2——CVE-2026-397065.3 MED5.6%
——2Missing Authorization vulnerability in Netro Systems Make My Trivia trivialy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Make My Trivia: from n/a through <= 1.1.0.8dCVE-2022-22082—5.6%
——2——CVE-2025-38043—5.6%
——2——