Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-6437—29.2%
——9——CVE-2024-30430—29.2%
——9——CVE-2018-6436—29.2%
——9——CVE-2014-0017—29.2%
——9——CVE-2015-5893—29.2%
——9——CVE-2007-5200—29.2%
——9——CVE-2024-274168.8 HIG29.2%
——9In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST
If we received HCI_EV_IO_CAPA_REQUEST while
HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote
does support SSP since otherwise this event shouldn't be generated.45dCVE-2023-53870—29.2%
——9——CVE-2026-24765—29.2%
——9——CVE-2024-2823—29.2%
——9——CVE-2017-10392—29.2%
——9——CVE-2017-10689—29.2%
——9——CVE-2017-14179—29.2%
——9——CVE-2024-5199—29.2%
——9——CVE-2026-157715.3 MED29.2%
——9Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)64dCVE-2026-38949—29.2%
——9——CVE-2018-0359—29.2%
——9——CVE-2025-70093—29.2%
——9——CVE-2026-40289—29.2%
——9——CVE-2026-791758.3 HIG29.2%
——9Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)21dCVE-2025-12845—29.2%
——9——CVE-2019-0061—29.2%
——9——CVE-2026-0699—29.2%
——9——CVE-2026-622067.1 HIG29.2%
——9OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform moderation actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.59dCVE-2019-20480—29.2%
——9——CVE-2026-603258.0 HIG29.2%
——9Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Access Manager executes to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).52dCVE-2024-1078—29.2%
——9——CVE-2004-0622—29.2%
——9——CVE-2026-713199.6 CRI29.2%
——9Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, handshake, or origin check before the channel is established. The updateOptions(), clearOptions(), and openInEditor() methods do not enforce the ensureDevAuthToken check that the other mutating methods use. openInEditor() reads the persisted behavior.openInEditor value and passes it to the launch-editor package, which spawns it as a child process. That value is settable through the equally unauthenticated updateOptions(). An attacker who can reach the HMR port can therefore chain updateOptions('behavior', { openInEditor: '<command>' }) then openInEditor('<any-existing-file>') to execute an arbitrary program on the developer's machine. This issue is fixed in 3.3.1.9dCVE-2024-4286—29.2%
——9——CVE-2026-0697—29.2%
——9——CVE-2009-1679—29.2%
——9——CVE-1999-0957—29.2%
——9——CVE-2008-3611—29.2%
——9——CVE-2021-2266—29.2%
——9——CVE-2011-3442—29.2%
——9——CVE-2001-0744—29.2%
——9——CVE-2004-1902—29.2%
——9——CVE-2026-576986.5 MED29.2%
——9Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.66dCVE-2024-20420—29.2%
——9——