Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,224
- High7,923
- Medium6,427
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-138178.8 HIG27.8%
——8Insufficient validation of untrusted input in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)76dCVE-2003-0574—27.8%
——8——CVE-2026-139019.6 CRI27.8%
——8Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)76dCVE-2025-457296.3 MED27.8%
——8D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services.77dCVE-2026-143879.6 CRI27.8%
——8Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)75dCVE-2026-40796—27.8%
——8——CVE-2026-144158.8 HIG27.8%
——8Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)76dCVE-2025-14777—27.8%
——8——CVE-2026-139038.8 HIG27.8%
——8Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)76dCVE-2026-139099.6 CRI27.8%
——8Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)76dCVE-2026-48878—27.8%
——8——CVE-2026-137929.6 CRI27.8%
——8Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)76dCVE-2022-45456—27.8%
——8——CVE-2024-10784—27.8%
——8——CVE-2026-44353—27.8%
——8——CVE-2026-151298.8 HIG27.8%
——8Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)68dCVE-2026-685537.1 HIG27.8%
——8Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation and is embedded into Redis keys at nine call sites in src/apps/relay/ns_ioalib_engine_impl.c. send_message_to_redis() in src/apps/relay/hiredis_libevent2.c then passes the attacker-controlled key as the format argument to redisAsyncCommand() while supplying only one variadic value, causing hiredis redisvFormatCommand() to read past the va_list. Exploitation can crash the coturn process and terminate active TURN sessions or disclose stack memory into Redis. This issue is fixed in version 4.13.0.7dCVE-1999-1036—27.8%
——8——CVE-2019-10194—27.8%
——8——CVE-2026-143979.6 CRI27.8%
——8Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)75dCVE-2013-3705—27.8%
——8——CVE-2010-20123—27.8%
——8——CVE-2026-141099.6 CRI27.8%
——8Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)76dCVE-2026-144169.6 CRI27.8%
——8Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)75dCVE-2026-53889.8 CRI27.8%
——8justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs, backslash-based relative URLs resolved as remote hosts, markup-breaking programmatic element/attribute names or HTML comments, raw </textarea> reintroduction through Markdown passthrough, or preserved <style>/<meta http-equiv=refresh>/<base href> tags in custom policies. Most custom-policy issues do not affect the default sanitize=True configuration; they primarily affect helper APIs, programmatic DOM construction, html_passthrough=True, and custom policies/transform pipelines.24dCVE-2026-144249.6 CRI27.8%
——8Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)75dCVE-2024-6374—27.8%
——8——CVE-2023-1001—27.8%
——8——CVE-2026-197464.3 MED27.8%
——8A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file traceroute.cmd. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.33dCVE-2020-12024—27.7%
——8——CVE-2014-8120—27.7%
——8——CVE-2024-51907—27.7%
——8——CVE-2026-30968—27.7%
——8——CVE-2024-35682—27.7%
——8——CVE-2025-65076—27.7%
——8——CVE-2023-40412—27.7%
——8——CVE-2016-5581—27.7%
——8——CVE-2022-4633—27.7%
——8——CVE-2024-10621—27.7%
——8——CVE-2024-39320—27.7%
——8——