Vulnerabilities exploitable today
379,275in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,375
- High8,542
- Medium7,076
- Low796
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-40822—34.9%
——10——CVE-2026-695666.8 MED34.9%
——10Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.10dCVE-2024-54308—34.9%
——10——CVE-2026-694906.8 MED34.9%
——10Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.8dCVE-2022-38446—34.9%
——10——CVE-2025-55695—34.9%
——10——CVE-2024-31098—34.9%
——10——CVE-2026-1177—34.9%
——10——CVE-2026-815748.2 HIG34.9%
——10In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format
specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory
and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and
remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this
vulnerability.23dCVE-2026-4351—34.9%
——10——CVE-2017-12547—34.9%
——10——CVE-2025-4838—34.9%
——10——CVE-2023-24062—34.9%
——10——CVE-2024-56139—34.9%
——10——CVE-2022-2617—34.9%
——10——CVE-2026-792928.3 HIG34.9%
——10Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)28dCVE-2023-24064—34.9%
——10——CVE-2025-61962—34.9%
——10——CVE-2018-5995—34.9%
——10——CVE-2024-4857—34.9%
——10——CVE-2025-5152—34.9%
——10——CVE-2023-48227—34.9%
——10——CVE-2024-22414—34.9%
——10——CVE-2025-48391—34.9%
——10——CVE-2026-41079—34.9%
——10——CVE-2026-748959.8 CRI34.9%
——10openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.23dCVE-2019-14410—34.9%
——10——CVE-2022-45417—34.9%
——10——CVE-2024-4616—34.9%
——10——CVE-2022-45831—34.9%
——10——CVE-2023-21921—34.9%
——10——CVE-2019-19043—34.9%
——10——CVE-2014-1520—34.8%
——10——CVE-2026-713506.8 MED34.9%
——10Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.2dCVE-2021-42373—34.9%
——10——CVE-2020-23060—34.9%
——10——CVE-2022-38448—34.9%
——10——CVE-2025-1741—34.9%
——10——CVE-2025-40712—34.9%
——10——CVE-2016-9278—34.9%
——10——