Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,224
- High7,917
- Medium6,422
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2015-3949—27.8%
——8——CVE-2026-11777—27.8%
——8——CVE-2020-24503—27.8%
——8——CVE-2026-490077.5 HIG27.8%
——8By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.21dCVE-2023-29275—27.8%
——8——CVE-2017-18018—27.8%
——8——CVE-2025-3329—27.8%
——8——CVE-2025-520259.4 CRI27.8%
——8An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulnerability arises because user input is directly inserted into a dynamic SQL query syntax without proper sanitization or parameterization. This allows an attacker to inject and execute arbitrary SQL code by submitting crafted input in the id parameter, leading to unauthorized data access or modification.74dCVE-2012-4082—27.8%
——8——CVE-2025-32687—27.8%
——8——CVE-2023-29281—27.8%
——8——CVE-2017-12351—27.8%
——8——CVE-2024-8892—27.8%
——8——CVE-2026-141209.6 CRI27.8%
——8Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)76dCVE-2025-54852—27.8%
——8——CVE-2025-15330—27.8%
——8——CVE-2025-52184—27.8%
——8——CVE-2023-5113—27.8%
——8——CVE-2024-23792—27.8%
——8——CVE-2026-201247.7 HIG27.8%
——8A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.41dCVE-2025-1365—27.8%
——8——CVE-2025-59129—27.8%
——8——CVE-2025-69437—27.8%
——8——CVE-2016-2972—27.8%
——8——CVE-2022-47040—27.8%
——8——CVE-2026-33955—27.8%
——8——CVE-2026-144199.6 CRI27.8%
——8Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)75dCVE-2024-7977—27.8%
——8——CVE-2026-138358.8 HIG27.8%
——8Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)76dCVE-2026-139158.8 HIG27.8%
——8Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)72dCVE-2021-27908—27.8%
——8——CVE-1999-1561—27.8%
——8——CVE-2021-1058—27.8%
——8——CVE-1999-0697—27.8%
——8——CVE-2025-46242—27.8%
——8——CVE-2011-10021—27.8%
——8——CVE-1999-1038—27.8%
——8——CVE-2026-25174—27.8%
——8——CVE-2017-13306—27.8%
——8——CVE-1999-0466—27.8%
——8——