Vulnerabilities exploitable today
363,765in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,923
- High12,256
- Medium7,477
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-20033—0.4%
——0——CVE-2022-47490—0.4%
——0——CVE-2018-9482—0.4%
——0——CVE-2024-58117—0.4%
——0——CVE-2025-20662—0.4%
——0——CVE-2021-0948—0.4%
——0——CVE-2023-21111—0.4%
——0——CVE-2024-29751—0.4%
——0——CVE-2022-22093—0.4%
——0——CVE-2024-29744—0.4%
——0——CVE-2022-25822—0.4%
——0——CVE-2024-20045—0.4%
——0——CVE-2023-33037—0.4%
——0——CVE-2024-29755—0.4%
——0——CVE-2025-48644—0.4%
——0——CVE-2024-53009—0.4%
——0——CVE-2025-68959—0.4%
——0——CVE-2022-47481—0.4%
——0——CVE-2022-47480—0.4%
——0——CVE-2025-53171—0.4%
——0——CVE-2025-58314—0.4%
——0——CVE-2018-9407—0.4%
——0——CVE-2021-3789—0.4%
——0——CVE-2026-447226.2 MED0.4%
——0pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected during encryption, causing encrypted entries to be written in AE-1 format and exposing the plaintext CRC32 checksum in the ZIP header and, for unseekable zip archives, in the datadescripter section, allowing an attacker who possesses the archive to brute-force candidate plaintexts for small or low-entropy files by comparing CRC32 values. This issue is fixed in version 0.4.0.35dCVE-2025-224247.8 HIG0.4%
——0In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.30dCVE-2025-32332—0.4%
——0——CVE-2024-20025—0.4%
——0——CVE-2022-48375—0.4%
——0——CVE-2023-21230—0.4%
——0——CVE-2022-38672—0.4%
——0——CVE-2023-21376—0.4%
——0——CVE-2021-25388—0.4%
——0——CVE-2025-33081—0.4%
——0——CVE-2026-0995—0.4%
——0——CVE-2026-23207—0.4%
——0——CVE-2025-64315—0.4%
——0——CVE-2025-31938—0.4%
——0Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.9dCVE-2022-33732—0.4%
——0——CVE-2026-31960—0.4%
——0——CVE-2022-38676—0.4%
——0——