Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,329
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-36859—32.7%
——10——CVE-2024-11689—32.7%
——10——CVE-2023-41168—32.7%
——10——CVE-2026-57940—32.7%
——10——CVE-2024-1289—32.7%
——10——CVE-2022-26269—32.7%
——10——CVE-2023-5598—32.7%
——10——CVE-2025-0969—32.7%
——10——CVE-2024-31230—32.7%
——10——CVE-2024-13323—32.7%
——10——CVE-2025-31798—32.7%
——10——CVE-2001-0190—32.7%
——10——CVE-2020-3961—32.7%
——10——CVE-2001-0124—32.7%
——10——CVE-2025-31755—32.7%
——10——CVE-2023-30606—32.7%
——10——CVE-2024-7016—32.7%
——10——CVE-2025-15068—32.6%
——10——CVE-2022-26868—32.7%
——10——CVE-2025-29181—32.7%
——10——CVE-2020-6014—32.7%
——10——CVE-2022-44361—32.7%
——10——CVE-2025-32235—32.7%
——10——CVE-2023-26276—32.7%
——10——CVE-2026-45809—32.7%
——10OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the watcherinfo generation functionality. An attacker can create an oversized watcher entry by sending a SUBSCRIBE Event: presence request with a long From URI, and then trigger presence.winfo watcherinfo XML generation for the same presentity. OpenSIPS copies the stored watcher URI into a fixed-size stack buffer, overflowing it and crashing the process. A remote attacker can crash an OpenSIPS worker in deployments that expose handle_subscribe() and allow watcherinfo (presence.winfo) generation. The issue is configuration-dependent because the presence and presence_xml modules must be loaded and SUBSCRIBE routing must be reachable. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.14dCVE-2026-177966.5 MED32.7%
——10Side-channel information leakage in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)50dCVE-2012-1752—32.7%
——10——CVE-2018-17977—32.7%
——10——CVE-2024-26310—32.7%
——10——CVE-2026-333827.5 HIG32.7%
——10Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.71dCVE-2023-6359—32.7%
——10——CVE-2025-31799—32.7%
——10——CVE-2026-28394—32.7%
——10——CVE-2026-60033—32.7%
——10Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.61dCVE-2026-115184.3 MED32.7%
——10A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /users.php of the component User Management Page. The manipulation of the argument fullname/username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.61dCVE-2026-760478.8 HIG32.7%
——10Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)33dCVE-2023-46099—32.7%
——10——CVE-2026-530499.8 CRI32.7%
——10In the Linux kernel, the following vulnerability has been resolved:
gfs2: add some missing log locking
Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(),
gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock,
but these functions require exclusion against concurrent transactions.
To fix that, add a non-locking __gfs2_log_flush() function. Then, in
gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log
flushing functions and __gfs2_log_flush().63dCVE-2025-30622—32.7%
——10——CVE-2026-876168.3 HIG32.7%
——10Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)12d