Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-429695.5 MED32.6%
——10Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.61dCVE-2025-14587—32.6%
——10——CVE-2022-33887—32.6%
——10——CVE-2025-13554—32.6%
——10——CVE-2014-4419—32.6%
——10——CVE-2017-12713—32.6%
——10——CVE-2025-13561—32.6%
——10——CVE-2025-13555—32.6%
——10——CVE-2017-12711—32.6%
——10——CVE-2025-13272—32.6%
——10——CVE-2025-15034—32.6%
——10——CVE-2025-14668—32.6%
——10——CVE-2026-20081—32.6%
——10——CVE-2000-0069—32.6%
——10——CVE-2026-760448.3 HIG32.6%
——10Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)31dCVE-2026-27906—32.6%
——10——CVE-2010-5157—32.6%
——10——CVE-2025-39591—32.6%
——10——CVE-2026-613475.5 MED32.6%
——10Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.36dCVE-2023-21513—32.6%
——10——CVE-2017-9780—32.6%
——10——CVE-2023-24400—32.6%
——10——CVE-2026-195608.8 HIG32.6%
——10Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)36dCVE-2025-0615—32.6%
——10——CVE-2026-347857.5 HIG32.6%
——10Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.59dCVE-2026-694575.5 MED32.6%
——10Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally.5dCVE-2026-619335.5 MED32.6%
——10Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.39dCVE-2026-311566.5 MED32.6%
——10A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file operation functions (fopen/ifstream/ofstream) for file reading and writing. An attacker can exploit this vulnerability by constructing a malicious path to read arbitrary readable files.79dCVE-2000-0067—32.6%
——10——CVE-2002-0915—32.6%
——10——CVE-2026-861539.1 CRI32.6%
——10A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.13dCVE-2025-15617—32.6%
——10——CVE-2024-4709—32.6%
——10——CVE-2023-45872—32.6%
——10——CVE-2024-5151—32.6%
——10——CVE-2023-25893—32.6%
——10——CVE-2026-195568.8 HIG32.6%
——10Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)36dCVE-2024-5715—32.6%
——10——CVE-2026-570749.1 CRI32.6%
——10XML::Bare versions through 0.53 for Perl have an unbounded character lookahead.
The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer.
Truncated strings such as "<a/" can trigger an out-of-bounds read.66dCVE-2024-13529—32.6%
——10——