Vulnerabilities exploitable today
352,969in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,334
- High8,050
- Medium7,230
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-21950—3.9%
——1——CVE-2025-54305—3.9%
——1——CVE-2024-45555—3.9%
——1——CVE-2025-49459—3.9%
——1——CVE-2025-12402—3.9%
——1——CVE-2024-21922—3.9%
——1——CVE-2025-12403—3.9%
——1——CVE-2026-24626—3.9%
——1——CVE-2026-502577.8 HIG3.9%
——1A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.9hCVE-2018-11986—3.9%
——1——CVE-2018-5905—3.9%
——1——CVE-2026-585596.5 MED3.9%
——1DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.12dCVE-2026-31772—3.9%
——1——CVE-2024-13960—3.9%
——1——CVE-2022-20416—3.9%
——1——CVE-2026-84098.8 HIG3.9%
——1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete. The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.4dCVE-2024-45759—3.9%
——1——CVE-2023-2866—3.9%
——1——CVE-2022-39904—3.9%
——1——CVE-2024-36071—3.9%
——1——CVE-2025-20934—3.9%
——1——CVE-2025-59890—3.9%
——1——CVE-2024-20325—3.9%
——1——CVE-2025-12456—3.9%
——1——CVE-2025-69634—3.9%
——1——CVE-2019-25474—3.9%
——1——CVE-2026-14899—3.9%
——1The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.5dCVE-2025-49877—3.9%
——1——CVE-2023-45864—3.9%
——1——CVE-2020-0208—3.9%
——1——CVE-2023-30565—3.9%
——1——CVE-2025-12401—3.9%
——1——CVE-2025-12400—3.9%
——1——CVE-2026-53428—3.9%
——1——CVE-2026-28468—3.9%
——1——CVE-2026-32838—3.9%
——1——CVE-2023-21671—3.9%
——1——CVE-2025-52923—3.9%
——1——CVE-2025-4277—3.9%
——1——CVE-2025-37825—3.9%
——1——