Vulnerabilities exploitable today
378,026in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,410
- Medium6,689
- Low753
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-21844—31.6%
——9——CVE-2022-20179—31.6%
——9——CVE-2025-31795—31.6%
——9——CVE-2025-31729—31.6%
——9——CVE-2019-25578—31.6%
——9——CVE-2010-2066—31.6%
——9——CVE-2008-3527—31.6%
——9——CVE-2024-22032—31.6%
——9——CVE-2025-24581—31.6%
——9——CVE-2020-8337—31.6%
——9——CVE-2019-256728.2 HIG31.6%
——9PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter. Attackers can submit POST requests to the comment submission endpoint with RLIKE-based boolean SQL injection payloads to extract sensitive database information.59dCVE-2023-21973—31.6%
——9——CVE-2004-0602—31.6%
——9——CVE-2024-47317—31.6%
——9——CVE-2026-3537—31.6%
——9——CVE-2022-20149—31.6%
——9——CVE-2003-0414—31.6%
——9——CVE-2020-29040—31.6%
——9——CVE-2026-704576.5 MED31.6%
——9rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. When snprintf truncates the formatted size string, the return value equals the number of characters that would have been written including the truncated portion, and this value may exceed the array length. The subsequent indexed write targets memory outside the intended array bounds, corrupting .bss memory.21dCVE-2023-21888—31.6%
——9——CVE-2026-336337.5 HIG31.6%
——9Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a PNG format declaration (f=100) whose payload exceeds twice the initial buffer capacity. The overflow is attacker-controlled in both length and content, causing DoS and potentially escalation to RCE itself. This issue has been fixed in version 0.47.0.59dCVE-2015-4869—31.6%
——9——CVE-2026-28138—31.6%
——9——CVE-2024-3331—31.6%
——9——CVE-2022-20151—31.6%
——9——CVE-2025-47150—31.6%
——9——CVE-2006-1274—31.6%
——9——CVE-2024-35498—31.6%
——9——CVE-1999-0907—31.6%
——9——CVE-2009-3564—31.6%
——9——CVE-2020-5990—31.6%
——9——CVE-2016-0909—31.6%
——9——CVE-2005-1036—31.6%
——9——CVE-2026-792478.3 HIG31.6%
——9Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)25dCVE-2026-21411—31.6%
——9——CVE-2025-1275—31.6%
——9——CVE-2023-43508—31.6%
——9——CVE-2025-8807—31.6%
——9——CVE-2026-790246.5 MED31.6%
——9Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)26dCVE-2020-16092—31.6%
——9——