Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-45130—28.9%
——9——CVE-2026-688967.8 HIG28.9%
——9Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.8dCVE-2022-47698—28.9%
——9——CVE-2024-56012—28.9%
——9——CVE-2024-51213—28.9%
——9——CVE-2023-47366—28.9%
——9——CVE-2023-38045—28.9%
——9——CVE-2025-46571—28.9%
——9——CVE-2026-178146.5 MED28.9%
——9Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)45dCVE-2026-157069.8 CRI28.9%
——9Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass.
This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.28dCVE-2026-3509—28.9%
——9——CVE-2024-43997—28.9%
——9——CVE-2025-32460—28.9%
——9——CVE-2023-2139—28.9%
——9——CVE-2026-910798.5 HIG28.9%
——9Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.3dCVE-2005-3112—28.9%
——9——CVE-2025-21627—28.9%
——9——CVE-2024-34765—28.9%
——9——CVE-2026-618713.7 LOW28.9%
——9ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.64dCVE-2016-7437—28.9%
——9——CVE-2013-5973—28.9%
——9——CVE-2026-177646.5 MED28.9%
——9Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)44dCVE-2005-1166—28.9%
——9——CVE-2022-44026—28.9%
——9——CVE-2015-3256—28.9%
——9——CVE-2026-476318.1 HIG28.9%
——9Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.51dCVE-2023-47372—28.9%
——9——CVE-2026-0850—28.9%
——9——CVE-2021-36994—28.9%
——9——CVE-2026-23806—28.9%
——9——CVE-2023-47368—28.9%
——9——CVE-2026-141088.8 HIG28.9%
——9Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)78dCVE-2022-47524—28.9%
——9——CVE-2023-32597—28.9%
——9——CVE-2023-29791—28.9%
——9——CVE-2026-177566.5 MED28.9%
——9Insufficient policy enforcement in Presentation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)44dCVE-2026-692897.8 HIG28.9%
——9Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.9dCVE-2023-1996—28.9%
——9——CVE-2023-47369—28.9%
——9——CVE-2012-0570—28.9%
——9——