Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-8466—32.0%
——10——CVE-2021-38928—32.0%
——10——CVE-2016-1261—32.0%
——10——CVE-2003-0048—32.0%
——10——CVE-2025-54679—32.0%
——10——CVE-2019-10367—32.0%
——10——CVE-2025-48373—32.0%
——10——CVE-2022-34746—32.0%
——10——CVE-2017-3568—32.0%
——10——CVE-2025-26940—32.0%
——10——CVE-2026-22787—32.0%
——10——CVE-2025-15463—32.0%
——10——CVE-2025-34238—32.0%
——10——CVE-2026-47137—32.0%
——10——CVE-2010-3384—32.0%
——10——CVE-2010-3360—32.0%
——10——CVE-2023-26077—32.0%
——10——CVE-2026-157706.5 MED32.0%
——10Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)68dCVE-2022-45087—32.0%
——10——CVE-2026-842874.3 MED32.0%
——10A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session Chat Interface. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.18dCVE-2011-4515—32.0%
——10——CVE-2025-7453—32.0%
——10——CVE-2023-28606—32.0%
——10——CVE-2026-790548.3 HIG32.0%
——10Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)26dCVE-2024-4860—32.0%
——10——CVE-2017-1000255—32.0%
——10——CVE-2026-822178.8 HIG32.0%
——10In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path such as ../.bashrc, an absolute path, or a ~-expanded path could therefore write or delete files outside the workspace with the privileges of the Theia backend OS user. Because the path argument is influenced by model output, it can be steered through indirect prompt injection, and in Agent Mode writes are applied without a confirmation dialog. Writing to a host-executed file such as a shell startup file or ~/.ssh/authorized_keys can escalate to code execution on the backend.20dCVE-2012-0044—32.0%
——10——CVE-2010-3535—32.0%
——10——CVE-2011-1832—32.0%
——10——CVE-2024-0336—32.0%
——10——CVE-2025-55102—32.0%
——10——CVE-2022-4983—32.0%
——10——CVE-2017-0710—32.0%
——10——CVE-2026-228996.5 MED32.0%
——10A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version:
File Station 5 5.5.6.5208 and later60dCVE-2016-10138—32.0%
——10——CVE-2024-31120—32.0%
——10——CVE-2024-49397—32.0%
——10——CVE-2022-29208—32.0%
——10——CVE-2023-46242—32.0%
——10——