Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,337
- High8,543
- Medium6,730
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-9713—31.1%
——9——CVE-2025-31539—31.1%
——9——CVE-2007-0288—31.1%
——9——CVE-2025-55009—31.1%
——9——CVE-2026-679917.5 HIG31.1%
——9crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.11dCVE-2024-13367—31.1%
——9——CVE-2026-789459.6 CRI31.1%
——9Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)24dCVE-2023-46047—31.1%
——9——CVE-2024-4643—31.1%
——9——CVE-2024-7057—31.1%
——9——CVE-2026-5986—31.1%
——9——CVE-2026-8290—31.1%
——9——CVE-2015-6426—31.1%
——9——CVE-2026-8123—31.1%
——9——CVE-2026-191719.6 CRI31.1%
——9Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)43dCVE-2026-782087.5 HIG31.1%
——9exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it in the generated workbook.19dCVE-2026-792579.6 CRI31.1%
——9Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)19dCVE-2025-11782—31.1%
——9——CVE-2026-792158.8 HIG31.1%
——9Integer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)19dCVE-2026-82494.3 MED31.1%
——9A flaw has been found in Open5GS up to 2.7.7. The impacted element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. This manipulation causes denial of service. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.58dCVE-2026-789379.6 CRI31.1%
——9Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)24dCVE-2026-82504.3 MED31.1%
——9A vulnerability has been found in Open5GS up to 2.7.7. This affects the function smf_n4_build_qos_flow_to_modify_list of the file /src/smf/n4-build.c of the component SMF. Such manipulation leads to denial of service. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.58dCVE-2024-29032—31.1%
——9——CVE-2026-791988.8 HIG31.1%
——9Use after free in Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)19dCVE-2026-8745—31.1%
——9——CVE-2020-35148.2 HIG31.1%
——9A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their Cisco FTD instance and execute commands with root privileges in the host namespace. The attacker must have valid credentials on the device.The vulnerability exists because a configuration file that is used at container startup has insufficient protections. An attacker could exploit this vulnerability by modifying a specific container configuration file on the underlying file system. A successful exploit could allow the attacker to execute commands with root privileges within the host namespace. This could allow the attacker to impact other running Cisco FTD instances or the host Cisco FXOS device.39dCVE-2023-46400—31.1%
——9——CVE-2008-0589—31.1%
——9——CVE-2026-791119.6 CRI31.1%
——9Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)24dCVE-2026-45556—31.1%
——9——CVE-2026-791289.6 CRI31.1%
——9Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)24dCVE-2015-3448—31.1%
——9——CVE-2014-5430—31.1%
——9——CVE-2011-2258—31.1%
——9——CVE-2026-792329.6 CRI31.1%
——9Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)19dCVE-2026-8318—31.1%
——9——CVE-2026-666777.6 HIG31.1%
——9Subscriber Broken Authentication in Leyka <= 3.32.3 versions.30dCVE-2024-32757—31.1%
——9——CVE-2024-22148—31.1%
——9——CVE-2026-861458.2 HIG31.1%
——9PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).10d