Vulnerabilities exploitable today
352,832in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,306
- High8,005
- Medium7,178
- Low677
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-43748—3.8%
——1——CVE-2024-283278.4 HIG3.8%
——1Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify router settings.19dCVE-2025-39917—3.8%
——1——CVE-2018-25222—3.8%
——1——CVE-2025-24788—3.8%
——1——CVE-2025-65922—3.8%
——1——CVE-2026-585905.4 MED3.8%
——1Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.13dCVE-2025-39723—3.8%
——1——CVE-2022-50335—3.8%
——1——CVE-2018-11988—3.8%
——1——CVE-2020-0315—3.8%
——1——CVE-2025-48188—3.8%
——1——CVE-2025-39963—3.8%
——1——CVE-2023-32492—3.8%
——1——CVE-2025-49849—3.8%
——1——CVE-2024-40885—3.8%
——1——CVE-2024-54126—3.8%
——1——CVE-2026-60089—3.8%
——1——CVE-2025-10089—3.8%
——1——CVE-2020-0107—3.8%
——1——CVE-2026-4816—3.8%
——1——CVE-2026-26074—3.8%
——1——CVE-2026-33535—3.8%
——1——CVE-2026-15630—3.8%
——1A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).4dCVE-2025-20199—3.8%
——1——CVE-2023-31310—3.8%
——1——CVE-2025-70310—3.8%
——1——CVE-2025-38164—3.8%
——1——CVE-2026-23249—3.8%
——1——CVE-2026-501109.2 CRI3.8%
——1Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credentials span a broad range of internal services, including database accounts, licensing, replication services, and third-party integrations, meaning successful exploitation of this vulnerability could provide an attacker with unauthorized access to multiple interconnected systems.26dCVE-2024-45983—3.8%
——1——CVE-2025-53869—3.8%
——1——CVE-2017-20218—3.8%
——1——CVE-2026-54543.3 LOW3.8%
——1A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown function of the file file res/raw/app.json of the component co.gridapp.organiser. Performing a manipulation of the argument SegmentWriteKey results in use of hard-coded cryptographic key
. The attack is only possible with local access. The exploit has been made public and could be used.3dCVE-2025-9881—3.8%
——1——CVE-2023-53522—3.8%
——1——CVE-2025-5731—3.8%
——1——CVE-2026-30292—3.8%
——1——CVE-2026-242324.3 MED3.8%
——1NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.6dCVE-2025-43883—3.8%
——1——