Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,384
- High8,718
- Medium6,702
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-49353—28.3%
——8——CVE-2024-2929—28.3%
——8——CVE-2024-27321—28.3%
——8——CVE-2021-42011—28.2%
——8——CVE-2026-6262—28.3%
——8——CVE-2024-37798—28.3%
——8——CVE-2024-1544—28.3%
——8——CVE-2024-57724—28.3%
——8——CVE-2025-67732—28.3%
——8——CVE-2023-25002—28.3%
——8——CVE-2024-56270—28.3%
——8——CVE-2010-3406—28.3%
——8——CVE-2024-35222—28.3%
——8——CVE-2025-0311—28.3%
——8——CVE-2024-6881—28.3%
——8——CVE-2026-92196.5 MED28.3%
——8Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging to other users.44dCVE-2025-59524—28.3%
——8——CVE-2023-46021—28.3%
——8——CVE-2024-47048—28.3%
——8——CVE-2024-27442—28.3%
——8——CVE-2026-13569—28.3%
——8——CVE-2025-6520—28.3%
——8——CVE-2026-157418.8 HIG28.3%
——8SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.18dCVE-2026-41145—28.3%
——8——CVE-2019-0185—28.3%
——8——CVE-2024-57720—28.3%
——8——CVE-2026-198024.3 MED28.3%
——8The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate an arbitrary attacker-hosted plugin, resulting in remote code execution on the server. The required nonce is emitted inline on all admin pages accessible to subscribers when WooCommerce is inactive, meaning any subscriber-level user can harvest it and trigger the exploit without any additional privileges.7dCVE-2024-8861—28.3%
——8——CVE-2013-1427—28.3%
——8——CVE-2025-13063—28.3%
——8——CVE-2019-10636—28.3%
——8——CVE-2026-1546—28.3%
——8——CVE-2026-191465.3 MED28.3%
——8Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)40dCVE-2024-57723—28.3%
——8——CVE-2022-34252—28.3%
——8——CVE-2021-46762—28.3%
——8——CVE-2026-861198.6 HIG28.3%
——8Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure.11dCVE-2025-30881—28.3%
——8——CVE-2026-875289.6 CRI28.3%
——8Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)7dCVE-2025-24949—28.3%
——8——