Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,379
- High8,748
- Medium6,795
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-5998—29.7%
——9——CVE-2025-68061—29.7%
——9——CVE-2019-19247—29.7%
——9——CVE-2025-66384—29.7%
——9——CVE-2012-6543—29.7%
——9——CVE-2026-109918.8 HIG29.7%
——9Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)58dCVE-2025-10272—29.7%
——9——CVE-2024-12314—29.7%
——9——CVE-2019-5692—29.7%
——9——CVE-2017-0492—29.7%
——9——CVE-2024-0970—29.7%
——9——CVE-2020-0113—29.7%
——9——CVE-2026-73348.8 HIG29.7%
——9Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)56dCVE-2011-4355—29.7%
——9——CVE-2006-1092—29.7%
——9——CVE-2025-10271—29.7%
——9——CVE-2024-20935—29.7%
——9——CVE-2006-1695—29.7%
——9——CVE-2022-45086—29.7%
——9——CVE-2025-47635—29.7%
——9——CVE-2026-109658.8 HIG29.7%
——9Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)58dCVE-2026-109598.8 HIG29.7%
——9Use after free in Input in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)58dCVE-2009-0317—29.7%
——9——CVE-2026-95167.5 HIG29.7%
——9Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws.
To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When decoding aborts through a Perl exception, for example a filter_json_object callback that croaks, the restore is skipped and the scalar is left with its string pointer offset into its own buffer and a shortened length.
When that scalar is later freed, the allocator receives an invalid pointer and the interpreter aborts. A single BOM prefixed document decoded with a throwing filter callback crashes any caller.58dCVE-2025-6783—29.7%
——9——CVE-2026-109638.8 HIG29.7%
——9Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)58dCVE-2024-11985—29.7%
——9——CVE-2025-68062—29.7%
——9——CVE-2026-571197.5 HIG29.7%
——9PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data. This vulnerability is fixed in 4.6.59.2dCVE-2026-553669.8 CRI29.7%
——9In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.1dCVE-2026-109578.8 HIG29.7%
——9Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)58dCVE-2026-631876.3 MED29.7%
——9Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on PR title step's inline echo command before piping the title to npx commitlint. A pull request title containing a single quote could terminate the echo string and append arbitrary shell commands on the GitHub Actions runner. The pull_request trigger used a read-only GITHUB_TOKEN and did not expose repository secrets, but injected commands could alter or disrupt the ephemeral workflow execution. This issue is fixed in version 1.41.0.9dCVE-2016-7474—29.7%
——9——CVE-2025-657537.5 HIG29.7%
——9An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.75dCVE-2012-4574—29.7%
——9——CVE-2026-624317.5 HIG29.7%
——9The logic to handle periodic Viridian STIMERs performs a division with an
unchecked user-controlled divisor value, that can be set to zero to cause a #DE
fault.52dCVE-2026-110288.8 HIG29.7%
——9Use after free in Media in Google Chrome on Linux and ChromeOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)57dCVE-2024-2783—29.7%
——9——CVE-2006-5808—29.7%
——9——CVE-2019-3827—29.7%
——9——