Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-109358.8 HIG33.4%
——10Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)62dCVE-2025-31225—33.4%
——10——CVE-2025-26594—33.4%
——10——CVE-2023-4646—33.4%
——10——CVE-2024-53623—33.4%
——10——CVE-2021-4419—33.4%
——10——CVE-2026-572728.3 HIG33.4%
——10GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound.
#### byPass command index-out-of-bound82dCVE-2025-28033—33.4%
——10——CVE-2025-27200—33.4%
——10——CVE-2019-25523—33.4%
——10——CVE-2025-26601—33.4%
——10——CVE-2021-4442—33.4%
——10——CVE-2024-23784—33.4%
——10——CVE-2023-24910—33.4%
——10——CVE-2019-13035—33.4%
——10——CVE-2024-50513—33.4%
——10——CVE-2022-29162—33.4%
——10——CVE-2017-4936—33.4%
——10——CVE-2024-445988.8 HIG33.4%
——10FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.80dCVE-2025-61976—33.4%
——10——CVE-2024-42172—33.4%
——10——CVE-2023-45220—33.4%
——10——CVE-2025-47999—33.4%
——10——CVE-2024-8140—33.4%
——10——CVE-2020-36756—33.4%
——10——CVE-2021-4423—33.4%
——10——CVE-2025-6208—33.4%
——10——CVE-2021-4420—33.4%
——10——CVE-2021-28246—33.4%
——10——CVE-2025-13574—33.4%
——10——CVE-2023-36237—33.4%
——10——CVE-2009-2691—33.4%
——10——CVE-2025-20210—33.4%
——10——CVE-2025-28029—33.4%
——10——CVE-2025-28027—33.4%
——10——CVE-2023-23418—33.4%
——10——CVE-2026-591617.5 HIG33.4%
——10Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does not enforce the TotalRows limit on the row r attribute, allowing a small XLSX file with a row number above 1048576 and no cell coordinate to make GetRows append empty rows up to the attacker-controlled index and consume excessive memory and CPU. This issue is fixed in version 2.11.0.68dCVE-2023-23417—33.4%
——10——CVE-2026-26013—33.4%
——10——CVE-2024-10414—33.4%
——10——