Vulnerabilities exploitable today
350,242in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,647
New KEV · 24H0
Exploit Today ≥ 701,583
Distribution · last window
- Critical1,426
- High4,734
- Medium3,925
- Low306
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-40703—1.2%
——0——CVE-2021-39766—1.2%
——0——CVE-2021-39791—1.2%
——0——CVE-2021-39777—1.2%
——0——CVE-2024-23695—1.2%
——0——CVE-2026-02675.5 MED1.2%
——0An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.13dCVE-2024-47056—1.2%
——0——CVE-2025-126947.8 HIG1.2%
——0A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior.20dCVE-2021-0686—1.2%
——0——CVE-2021-0680—1.2%
——0——CVE-2026-449692.5 LOW1.2%
——0dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote those records to dbt-mcp.log when DBT_MCP_SERVER_FILE_LOGGING=true, preserving sensitive sql_query, vars, and node_selection values in plaintext without automatic rotation or deletion. This issue is fixed in version 1.17.1.3dCVE-2024-23696—1.2%
——0——CVE-2024-33034—1.2%
——0——CVE-2024-33044—1.2%
——0——CVE-2023-22382—1.2%
——0——CVE-2021-25484—1.2%
——0——CVE-2026-33451—1.2%
——0——CVE-2021-39788—1.2%
——0——CVE-2026-32655—1.2%
——0——CVE-2022-42500—1.2%
——0——CVE-2023-31225—1.2%
——0——CVE-2023-4328—1.2%
——0——CVE-2024-31314—1.2%
——0——CVE-2022-48431—1.2%
——0——CVE-2026-22676—1.2%
——0——CVE-2023-4327—1.2%
——0——CVE-2022-20146—1.2%
——0——CVE-2021-0999—1.2%
——0——CVE-2022-20466—1.2%
——0——CVE-2022-25817—1.2%
——0——CVE-2026-42477—1.2%
——0——CVE-2026-532575.5 MED1.2%
——0In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: enforce HE/EHT cap/oper consistency
Xiang Mei reports that mac80211 could crash if eht_cap is set
but eht_oper isn't. Rather than fixing that for the individual
user(s), enforce that both HE/EHT have consistent elements.12dCVE-2025-27723—1.2%
——0——CVE-2021-25362—1.2%
——0——CVE-2024-23711—1.2%
——0——CVE-2026-42306—1.2%
——0——CVE-2026-576904.3 MED1.2%
——0Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.18dCVE-2023-20780—1.2%
——0——CVE-2021-1010—1.2%
——0——CVE-2026-48986—1.2%
——0——