Vulnerabilities exploitable today
352,832in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,306
- High8,005
- Medium7,178
- Low677
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-46293—3.8%
——1——CVE-2026-558073.1 LOW3.8%
——1Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.11dCVE-2025-48111—3.8%
——1——CVE-2024-39574—3.8%
——1——CVE-2025-62185—3.8%
——1——CVE-2026-23648—3.8%
——1——CVE-2025-4966—3.8%
——1——CVE-2025-49269—3.8%
——1——CVE-2020-9089—3.8%
——1——CVE-2025-47543—3.8%
——1——CVE-2025-30956—3.8%
——1——CVE-2025-49317—3.8%
——1——CVE-2026-57453—3.8%
——1——CVE-2025-13397—3.8%
——1——CVE-2025-38340—3.8%
——1——CVE-2025-47647—3.8%
——1——CVE-2025-47594—3.8%
——1——CVE-2025-47451—3.8%
——1——CVE-2025-24268—3.8%
——1——CVE-2026-32606—3.8%
——1——CVE-2026-63683—3.8%
——1Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.4dCVE-2025-38728—3.8%
——1——CVE-2025-53261—3.8%
——1——CVE-2026-63685—3.8%
——1Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causing major data corruption or site compromise.4dCVE-2025-53347—3.8%
——1——CVE-2019-25616—3.8%
——1——CVE-2023-53427—3.8%
——1——CVE-2026-42953—3.8%
——1The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution.18dCVE-2025-69268—3.8%
——1——CVE-2025-54956—3.8%
——1——CVE-2025-47519—3.8%
——1——CVE-2026-539075.4 MED3.8%
——1MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the application logo can upload a crafted SVG file containing malicious JavaScript code that is executed when the logo is rendered or opened.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.21dCVE-2021-0931—3.8%
——1——CVE-2025-71176—3.8%
——1——CVE-2025-65962—3.8%
——1——CVE-2026-565833.1 LOW3.8%
——1HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.5dCVE-2025-24916—3.8%
——1——CVE-2025-28984—3.8%
——1——CVE-2025-47448—3.8%
——1——CVE-2025-53264—3.8%
——1——