Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,224
- High7,917
- Medium6,422
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-55071—27.8%
——8——CVE-2022-3685—27.8%
——8——CVE-2008-5387—27.8%
——8——CVE-2026-143989.6 CRI27.8%
——8Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)75dCVE-2024-6272—27.8%
——8——CVE-2026-140098.8 HIG27.8%
——8Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)77dCVE-2026-151128.8 HIG27.8%
——8Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)68dCVE-2024-41353—27.8%
——8——CVE-2023-29273—27.8%
——8——CVE-2026-139209.6 CRI27.8%
——8Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)77dCVE-2024-9892—27.8%
——8——CVE-2026-528736.9 MED27.8%
——8Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and registers an onHeadersReceived hook that removes the Content-Security-Policy header from every response in that session. The redeem window also lacks a setWindowOpenHandler restriction, so script injection in sub.wyzie.io, a loaded third-party resource, or a site reached through navigation executes without CSP constraints and can affect additional windows and persistent session storage. A user must open the Wyzie API key redemption window, and exploitation requires attacker-controlled script content in a loaded page. The resulting renderer script can invoke renderer-exposed application functionality and can be chained with other vulnerabilities to access internal services or sensitive data. This issue is fixed in version 2.6.0.7dCVE-2023-39394—27.8%
——8——CVE-2024-9699—27.8%
——8——CVE-2025-556596.5 MED27.8%
——8A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.55dCVE-2024-23792—27.8%
——8——CVE-2026-139188.8 HIG27.8%
——8Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)72dCVE-2025-52184—27.8%
——8——CVE-2025-520259.4 CRI27.8%
——8An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulnerability arises because user input is directly inserted into a dynamic SQL query syntax without proper sanitization or parameterization. This allows an attacker to inject and execute arbitrary SQL code by submitting crafted input in the id parameter, leading to unauthorized data access or modification.74dCVE-2012-4082—27.8%
——8——CVE-2016-7597—27.8%
——8——CVE-2019-10143—27.8%
——8——CVE-2006-4981—27.8%
——8——CVE-2025-3329—27.8%
——8——CVE-2025-27955—27.8%
——8——CVE-2026-54515—27.8%
——8——CVE-2025-49406—27.8%
——8——CVE-2023-26389—27.8%
——8——CVE-2026-137899.6 CRI27.8%
——8Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)76dCVE-2023-6645—27.8%
——8——CVE-2026-139349.6 CRI27.8%
——8Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)77dCVE-2018-10647—27.8%
——8——CVE-2026-11776—27.8%
——8——CVE-2010-2392—27.8%
——8——CVE-2026-3995—27.8%
——8——CVE-2023-5337—27.8%
——8——CVE-2016-3713—27.8%
——8——CVE-2021-46893—27.8%
——8——CVE-2017-9958—27.8%
——8——CVE-2023-26409—27.8%
——8——