Vulnerabilities exploitable today
363,707in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,921
- High12,266
- Medium7,473
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-20763—0.2%
——0——CVE-2026-28550—0.2%
——0——CVE-2024-44096—0.2%
——0——CVE-2026-438207.7 HIG0.2%
——0NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.28dCVE-2024-20115—0.2%
——0——CVE-2025-596146.7 MED0.2%
——0Memory Corruption when sending random number generator command with insufficient output buffer size.30dCVE-2025-22414—0.2%
——0——CVE-2024-20123—0.1%
——0——CVE-2023-33110—0.1%
——0——CVE-2025-27036—0.2%
——0——CVE-2024-20124—0.1%
——0——CVE-2024-39439—0.1%
——0——CVE-2018-9420—0.1%
——0——CVE-2025-26437—0.1%
——0——CVE-2024-29787—0.1%
——0——CVE-2023-38463—0.1%
——0——CVE-2023-38441—0.1%
——0——CVE-2026-34859—0.1%
——0——CVE-2023-38461—0.1%
——0——CVE-2024-47018—0.1%
——0——CVE-2024-20112—0.1%
——0——CVE-2026-20444—0.1%
——0——CVE-2024-25649—0.1%
——0——CVE-2024-44099—0.1%
——0——CVE-2026-471224.2 MED0.1%
——0Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. After `_performedStage1Installation = YES`, new connections to the registered Mach service `<bundleId>-spki` are accepted from any local process without team-ID or code-signing checks. As of time of publication, no known patched versions are available.16dCVE-2026-41962—0.1%
——0——CVE-2022-20396—0.1%
——0——CVE-2023-20826—0.1%
——0——CVE-2026-20707—0.1%
——0Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.9dCVE-2025-20745—0.1%
——0——CVE-2025-10237—0.1%
——0——CVE-2025-31712—0.1%
——0——CVE-2025-21024—0.1%
——0——CVE-2023-40650—0.1%
——0——CVE-2023-38465—0.1%
——0——CVE-2025-26445—0.1%
——0——CVE-2024-39433—0.1%
——0——CVE-2025-48577—0.1%
——0——CVE-2018-9421—0.1%
——0——CVE-2023-40641—0.1%
——0——