Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-45393—32.6%
——10——CVE-2023-24408—32.6%
——10——CVE-2008-2372—32.6%
——10——CVE-2007-4277—32.6%
——10——CVE-2026-195598.8 HIG32.6%
——10Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)35dCVE-2024-1902—32.6%
——10——CVE-2025-1791—32.6%
——10——CVE-2023-29720—32.6%
——10——CVE-2026-287989.0 CRI32.6%
——10ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an externally reachable domain using a Cloudflare Tunnel) to make requests to internal localhost services. This results in unauthenticated access to internal-only endpoints and sensitive local services when the product is reachable from the Internet through a Cloudflare Tunnel. This issue has been patched in version 1.5.3.59dCVE-2026-935757.5 HIG32.6%
——10A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Remaining Length', allowing an attacker to bypass size limits. This leads to excessive memory and CPU consumption, resulting in a denial of service (DoS) due to an OutOfMemoryError.3dCVE-2025-63372—32.6%
——10——CVE-2025-50056—32.6%
——10——CVE-2026-195568.8 HIG32.6%
——10Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)35dCVE-2026-694575.5 MED32.6%
——10Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally.5dCVE-2023-23874—32.6%
——10——CVE-2026-32713—32.6%
——10——CVE-2026-627465.5 MED32.6%
——10Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.36dCVE-2015-4837—32.6%
——10——CVE-2026-24783—32.6%
——10——CVE-2026-5970—32.6%
——10——CVE-2017-8831—32.6%
——10——CVE-2023-25899—32.6%
——10——CVE-2015-1144—32.5%
——10——CVE-2020-35923—32.5%
——10——CVE-2020-35921—32.5%
——10——CVE-2005-0352—32.5%
——10——CVE-2021-40829—32.5%
——10——CVE-2013-3496—32.5%
——10——CVE-2024-49396—32.5%
——10——CVE-2019-19056—32.5%
——10——CVE-2021-40830—32.5%
——10——CVE-2023-48229—32.5%
——10——CVE-2025-68540—32.5%
——10——CVE-2024-1563—32.5%
——10——CVE-2024-47311—32.5%
——10——CVE-2010-4083—32.5%
——10——CVE-2017-1125—32.5%
——10——CVE-2025-9687—32.5%
——10——CVE-2019-15343—32.5%
——10——CVE-2022-47187—32.5%
——10——