Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,224
- High7,921
- Medium6,426
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2002-0673—27.8%
——8——CVE-2003-0597—27.8%
——8——CVE-2026-167026.5 MED27.8%
——8IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference.2dCVE-2001-1173—27.8%
——8——CVE-1999-0329—27.8%
——8——CVE-2010-20042—27.8%
——8——CVE-2026-140058.8 HIG27.8%
——8Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)77dCVE-2024-12836—27.8%
——8——CVE-2015-3142—27.8%
——8——CVE-2026-26519.0 CRI27.8%
——8A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.57dCVE-1999-0295—27.8%
——8——CVE-2002-1786—27.8%
——8——CVE-1999-0963—27.8%
——8——CVE-2026-143909.6 CRI27.8%
——8Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)75dCVE-2026-140788.8 HIG27.8%
——8Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)76dCVE-2005-3719—27.8%
——8——CVE-2026-140368.8 HIG27.8%
——8Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)76dCVE-2025-45663—27.8%
——8——CVE-2012-0563—27.8%
——8——CVE-2021-1060—27.8%
——8——CVE-2026-581873.7 LOW27.8%
——8The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.47dCVE-2001-0944—27.8%
——8——CVE-2011-2147—27.8%
——8——CVE-2026-144179.6 CRI27.8%
——8Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)75dCVE-1999-1039—27.8%
——8——CVE-2026-42660—27.8%
——8——CVE-2026-140179.6 CRI27.8%
——8Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)77dCVE-2001-1171—27.8%
——8——CVE-2025-67507—27.8%
——8——CVE-2018-1206—27.8%
——8——CVE-2026-197454.3 MED27.8%
——8A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing a manipulation of the argument sessionKey can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.33dCVE-2023-21598—27.8%
——8——CVE-2000-0215—27.8%
——8——CVE-2026-141028.8 HIG27.8%
——8Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)76dCVE-1999-0852—27.8%
——8——CVE-2013-4288—27.8%
——8——CVE-2009-20004—27.8%
——8——CVE-2025-614987.5 HIG27.8%
——8A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet.74dCVE-2026-140258.8 HIG27.8%
——8Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)77dCVE-2025-35765.9 MED27.8%
——8A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.15d