Vulnerabilities exploitable today
354,470in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,643
- High9,463
- Medium7,694
- Low694
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-0326—4.6%
——1——CVE-2026-599508.1 HIG4.6%
——1The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.13dCVE-2024-36339—4.6%
——1——CVE-2022-50435—4.6%
——1——CVE-2017-0751—4.6%
——1——CVE-2025-23345—4.6%
——1——CVE-2025-33205—4.6%
——1——CVE-2026-49440—4.6%
——1——CVE-2023-53537—4.6%
——1——CVE-2025-12418—4.6%
——1——CVE-2020-0220—4.6%
——1——CVE-2026-48065—4.6%
——1——CVE-2026-28073—4.6%
——1——CVE-2025-38636—4.6%
——1——CVE-2026-545457.1 HIG4.6%
——1wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once before writing extracted modules, so a crafted filename containing overlapping traversal sequences such as ....// collapses to ../ after sanitization and lets the final output path escape the selected output directory, allowing an attacker who can cause a user to run wakaru --unpack on a malicious bundle to write files outside that directory and, depending on the target path and environment, potentially achieve code execution. This issue is fixed in @wakaru/cli 1.4.0.11hCVE-2025-13990—4.6%
——1——CVE-2020-9210—4.6%
——1——CVE-2026-43492—4.6%
——1——CVE-2023-53219—4.6%
——1——CVE-2026-437237.8 HIG4.6%
——1A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.2dCVE-2025-31572—4.6%
——1——CVE-2024-11035—4.6%
——1——CVE-2020-9146—4.6%
——1——CVE-2024-34644—4.6%
——1——CVE-2025-55252—4.6%
——1——CVE-2023-53536—4.6%
——1——CVE-2025-40741—4.6%
——1——CVE-2020-36965—4.6%
——1——CVE-2026-45935—4.6%
——1——CVE-2026-53511—4.6%
——1calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by calibre, including through Add books or Edit books, by embedding a custom column definition with a python: template in calibre:user_metadata that is passed unsanitized to exec() in the template formatter. This issue is fixed in version 9.10.0.20dCVE-2020-0448—4.6%
——1——CVE-2025-68891—4.6%
——1——CVE-2021-1912—4.6%
——1——CVE-2025-68892—4.6%
——1——CVE-2025-22669—4.6%
——1——CVE-2025-68874—4.6%
——1——CVE-2023-53311—4.6%
——1——CVE-2020-0186—4.6%
——1——CVE-2026-141334.2 MED4.6%
——1Race in History Embeddings in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)29dCVE-2023-41818—4.6%
——1——