Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2000-0072—26.5%
——8——CVE-2025-11041—26.5%
——8——CVE-2025-2200—26.5%
——8——CVE-2025-11104—26.5%
——8——CVE-2026-648328.8 HIG26.5%
——8FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.49dCVE-2021-4444—26.5%
——8——CVE-2025-62100—26.5%
——8——CVE-2015-1094—26.5%
——8——CVE-2026-41056—26.5%
——8——CVE-2026-34023—26.5%
——8——CVE-2026-20687—26.5%
——8——CVE-2020-4411—26.5%
——8——CVE-2020-5573—26.5%
——8——CVE-2025-54525—26.5%
——8——CVE-2026-43347—26.5%
——8——CVE-2025-59942—26.5%
——8——CVE-2026-32057—26.5%
——8——CVE-2024-5486—26.5%
——8——CVE-2026-27702—26.5%
——8——CVE-2025-0739—26.5%
——8——CVE-2026-45665—26.5%
——8——CVE-2025-62151—26.5%
——8——CVE-2024-4365—26.5%
——8——CVE-2025-11478—26.5%
——8——CVE-2025-2199—26.5%
——8——CVE-2026-6903—26.5%
——8——CVE-2023-21990—26.5%
——8——CVE-2024-44001—26.5%
——8——CVE-2026-89738.8 HIG26.5%
——8Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Thunderbird 151.54dCVE-2023-2417—26.5%
——8——CVE-2013-3408—26.5%
——8——CVE-2026-598867.5 HIG26.5%
——8pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.56dCVE-2007-2654—26.5%
——8——CVE-2001-1079—26.5%
——8——CVE-2024-57577—26.5%
——8——CVE-2026-744317.5 HIG26.5%
——8In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix potential infinite loop in rxrpc_recvmsg()
Fix the wait in rxrpc_recvmsg() also take check the oob queue.30dCVE-2012-0652—26.5%
——8——CVE-2022-27495—26.5%
——8——CVE-2010-0318—26.5%
——8——CVE-2011-0800—26.5%
——8——