Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-1082—32.9%
——10——CVE-2021-4396—32.9%
——10——CVE-2020-5378—32.9%
——10——CVE-2025-64363—32.9%
——10——CVE-2022-42944—32.9%
——10——CVE-2023-22514—32.9%
——10——CVE-2006-1797—32.9%
——10——CVE-2024-4711—32.9%
——10——CVE-2014-6551—32.9%
——10——CVE-2022-50925—32.9%
——10——CVE-2008-4974—32.9%
——10——CVE-2026-257825.3 MED32.9%
——10Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.77dCVE-2020-7319—32.9%
——10——CVE-2025-26305—32.9%
——10——CVE-2013-4035—32.9%
——10——CVE-2008-4965—32.9%
——10——CVE-2008-4948—32.9%
——10——CVE-2008-4958—32.9%
——10——CVE-2022-42936—32.9%
——10——CVE-2025-64364—32.9%
——10——CVE-2026-156437.3 HIG32.9%
——10AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authenticated user to exfiltrate AWS temporary security credentials to an arbitrary endpoint via a crafted next_token parameter. The server does not validate that pagination URLs point back to the expected HealthLake endpoint, allowing an actor to redirect subsequent requests to an actor-controlled server.
Its recommended to upgrade to version 0.0.14 or later.69dCVE-2026-177099.6 CRI32.9%
——10Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)50dCVE-2026-54028.8 HIG32.9%
——10TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution70dCVE-2025-4609—32.9%
——10——CVE-2025-68544—32.9%
——10——CVE-2024-6934—32.9%
——10——CVE-2008-4939—32.9%
——10——CVE-2008-4942—32.9%
——10——CVE-2025-64359—32.9%
——10——CVE-2022-42446—32.9%
——10——CVE-2020-5376—32.9%
——10——CVE-2025-0659—32.9%
——10——CVE-2023-25145—32.9%
——10——CVE-2021-4397—32.9%
——10——CVE-2024-10197—32.9%
——10——CVE-2025-7127—32.9%
——10——CVE-2026-108838.8 HIG32.9%
——10Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)62dCVE-2023-40969—32.9%
——10——CVE-2017-1544—32.9%
——10——CVE-2025-2087—32.9%
——10——