Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,381
- High8,758
- Medium6,799
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-21357—0.4%
——0——CVE-2024-40651—0.4%
——0——CVE-2023-21319—0.4%
——0——CVE-2023-38439—0.4%
——0——CVE-2025-26440—0.4%
——0——CVE-2023-21327—0.4%
——0——CVE-2023-38437—0.4%
——0——CVE-2026-841855.9 MED0.4%
——0A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users.9dCVE-2025-36920—0.4%
——0——CVE-2025-26436—0.4%
——0——CVE-2025-47316—0.4%
——0——CVE-2026-351546.3 MED0.4%
——0Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an
improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation.45dCVE-2023-30863—0.4%
——0——CVE-2025-47347—0.4%
——0——CVE-2023-30929—0.4%
——0——CVE-2026-43342—0.4%
——0——CVE-2025-47315—0.4%
——0——CVE-2024-22009—0.4%
——0——CVE-2025-47327—0.4%
——0——CVE-2025-26431—0.4%
——0——CVE-2023-21301—0.4%
——0——CVE-2026-493016.2 MED0.4%
——0Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.22dCVE-2023-33918—0.4%
——0——CVE-2024-43064—0.4%
——0——CVE-2025-47314—0.4%
——0——CVE-2024-53028—0.4%
——0——CVE-2018-9407—0.4%
——0——CVE-2026-61027.8 HIG0.4%
——0MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the NTIOLib_X64.sys driver. The issue results from insufficient validation of the origin of commands. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28935.49dCVE-2022-38677—0.4%
——0——CVE-2023-30941—0.4%
——0——CVE-2023-40112—0.4%
——0——CVE-2024-25989—0.4%
——0——CVE-2023-52346—0.4%
——0——CVE-2023-21107—0.4%
——0——CVE-2025-48563—0.4%
——0——CVE-2023-21352—0.4%
——0——CVE-2022-47328—0.4%
——0——CVE-2025-21482—0.4%
——0——CVE-2024-47123—0.4%
——0——CVE-2023-30924—0.4%
——0——