Vulnerabilities exploitable today
364,217in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,674
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,625
- High10,725
- Medium5,987
- Low568
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-33043—0.6%
——0——CVE-2022-20399—0.6%
——0——CVE-2026-44944—0.6%
——0An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket.
This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.23dCVE-2024-47027—0.6%
——0——CVE-2023-20725—0.6%
——0——CVE-2025-20643—0.6%
——0——CVE-2026-21013—0.6%
——0——CVE-2022-20398—0.6%
——0——CVE-2018-9371—0.6%
——0——CVE-2026-755873.6 LOW0.6%
——0Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-007163dCVE-2026-46194—0.6%
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.12dCVE-2026-21026—0.6%
——0——CVE-2026-471665.7 MED0.6%
——0ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.30dCVE-2023-21187—0.6%
——0——CVE-2022-32636—0.6%
——0——CVE-2022-30753—0.6%
——0——CVE-2023-20694—0.6%
——0——CVE-2024-29753—0.6%
——0——CVE-2023-20783—0.6%
——0——CVE-2022-32647—0.6%
——0——CVE-2021-0483—0.6%
——0——CVE-2021-25501—0.6%
——0——CVE-2025-32328—0.6%
——0——CVE-2026-21031—0.6%
——0——CVE-2023-20716—0.6%
——0——CVE-2026-21017—0.6%
——0——CVE-2026-210597.1 HIG0.6%
——0Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.4dCVE-2025-48647—0.6%
——0——CVE-2023-32883—0.6%
——0——CVE-2023-20621—0.6%
——0——CVE-2023-20784—0.6%
——0——CVE-2023-35677—0.6%
——0——CVE-2023-20749—0.6%
——0——CVE-2025-15595—0.6%
——0——CVE-2024-25986—0.6%
——0——CVE-2022-48439—0.6%
——0——CVE-2026-466924.1 MED0.6%
——0ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-write in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.30dCVE-2022-47346—0.6%
——0——CVE-2026-348226.4 MED0.6%
——0Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.29dCVE-2023-20996—0.6%
——0——