Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2014-6473—32.0%
——10——CVE-2026-32400—32.0%
——10——CVE-2025-8796—32.0%
——10——CVE-2024-35683—32.0%
——10——CVE-2026-20144—32.0%
——10——CVE-2025-47600—32.0%
——10——CVE-2023-32488—32.0%
——10——CVE-2026-32393—32.0%
——10——CVE-2026-134469.8 CRI32.0%
——10IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.61dCVE-2025-12315—32.0%
——10——CVE-2024-43219—32.0%
——10——CVE-2026-273555.3 MED32.0%
——10Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.60dCVE-2026-789348.3 HIG32.0%
——10Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)25dCVE-2026-84459.8 CRI32.0%
——10justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters are escaped, characters such as < and > are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g. <script>) or text from RCDATA/RAWTEXT-parsed elements like <title>, <textarea>, <noscript>, and <plaintext> — can be emitted as raw HTML in the Markdown output, enabling a sanitizer bypass and potential cross-site scripting when that output is rendered.28dCVE-2024-3600—32.0%
——10——CVE-2021-1597—32.0%
——10——CVE-2024-32812—32.0%
——10——CVE-2020-10069—32.0%
——10——CVE-2021-0237—32.0%
——10——CVE-2010-2070—32.0%
——10——CVE-2021-0239—32.0%
——10——CVE-2021-27893—32.0%
——10——CVE-2006-5405—32.0%
——10——CVE-2001-0635—32.0%
——10——CVE-2024-32129—32.0%
——10——CVE-2024-1160—32.0%
——10——CVE-2026-638579.8 CRI32.0%
——10In the Linux kernel, the following vulnerability has been resolved:
net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()
The transmit loop in airoha_dev_xmit() reads fragment address and length
during its final iteration, when the loop index equals
skb_shinfo(skb)->nr_frags, at which point the fragment data is
uninitialized. While these values are never consumed, the read itself is
unsafe and may trigger a page fault. Fix this by avoiding the fragment
read on the last iteration.
Additionally, move the skb pointer from the first to the last used packet
descriptor, so that airoha_qdma_tx_napi_poll() defers freeing the skb
until the final descriptor is processed.56dCVE-2025-26370—32.0%
——10——CVE-2025-60852—32.0%
——10——CVE-2023-29011—32.0%
——10——CVE-2023-1158—32.0%
——10——CVE-2023-37025—32.0%
——10——CVE-2021-1067—32.0%
——10——CVE-2024-46300—32.0%
——10——CVE-2019-20700—32.0%
——10——CVE-2025-32971—32.0%
——10——CVE-2023-37031—32.0%
——10——CVE-2024-41816—32.0%
——10——CVE-2023-30963—32.0%
——10——CVE-2026-35194—32.0%
——10——