Vulnerabilities exploitable today
352,832in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,306
- High8,005
- Medium7,178
- Low677
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-53264—3.8%
——1——CVE-2025-48243—3.8%
——1——CVE-2025-53203—3.8%
——1——CVE-2025-31260—3.8%
——1——CVE-2026-40386—3.8%
——1——CVE-2025-47609—3.8%
——1——CVE-2025-30994—3.8%
——1——CVE-2023-53675—3.8%
——1——CVE-2025-47447—3.8%
——1——CVE-2024-42050—3.8%
——1——CVE-2025-47448—3.8%
——1——CVE-2025-47594—3.8%
——1——CVE-2025-47647—3.8%
——1——CVE-2025-47543—3.8%
——1——CVE-2025-24268—3.8%
——1——CVE-2020-9089—3.8%
——1——CVE-2025-13397—3.8%
——1——CVE-2025-49317—3.8%
——1——CVE-2025-4966—3.8%
——1——CVE-2025-30956—3.8%
——1——CVE-2025-49269—3.8%
——1——CVE-2025-38340—3.8%
——1——CVE-2026-32606—3.8%
——1——CVE-2026-57453—3.8%
——1——CVE-2025-49285—3.8%
——1——CVE-2025-29005—3.8%
——1——CVE-2025-30629—3.8%
——1——CVE-2026-558073.1 LOW3.8%
——1Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.11dCVE-2025-46293—3.8%
——1——CVE-2015-20112—3.8%
——1——CVE-2025-47542—3.8%
——1——CVE-2025-49284—3.8%
——1——CVE-2025-47446—3.8%
——1——CVE-2023-20514—3.8%
——1——CVE-2026-64793—3.8%
——1Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.4dCVE-2025-47451—3.8%
——1——CVE-2026-24345—3.8%
——1——CVE-2026-23648—3.8%
——1——CVE-2025-49286—3.8%
——1——CVE-2025-49283—3.8%
——1——