Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,453
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-36765—26.4%
——8——CVE-2024-53702—26.4%
——8——CVE-2024-1766—26.4%
——8——CVE-2026-25189—26.4%
——8——CVE-2021-0091—26.4%
——8——CVE-2023-6673—26.4%
——8——CVE-2023-45779—26.4%
——8——CVE-2018-17492—26.4%
——8——CVE-2024-52452—26.4%
——8——CVE-2019-25486—26.4%
——8——CVE-2022-46774—26.4%
——8——CVE-2025-10310—26.4%
——8——CVE-2014-1949—26.4%
——8——CVE-2024-47816—26.4%
——8——CVE-2024-29906—26.4%
——8——CVE-2024-51543—26.4%
——8——CVE-2023-22347—26.4%
——8——CVE-2008-1246—26.4%
——8——CVE-2020-6199—26.4%
——8——CVE-2025-1577—26.4%
——8——CVE-2021-3732—26.4%
——8——CVE-2023-22349—26.4%
——8——CVE-2024-40488—26.4%
——8——CVE-2025-69267—26.4%
——8——CVE-2024-31255—26.4%
——8——CVE-2026-613597.8 HIG26.4%
——8Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.33dCVE-2024-12327—26.4%
——8——CVE-2024-37741—26.4%
——8——CVE-2026-26985—26.4%
——8——CVE-2024-45837—26.4%
——8——CVE-2022-40261—26.4%
——8——CVE-2025-48414—26.4%
——8——CVE-2013-0580—26.4%
——8——CVE-2026-498385.9 MED26.4%
——8GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be rejected as a malformed AS_PATH instead reaches an unchecked `p.Value[0]` access, allowing a configured confederation eBGP peer to trigger a denial of service. Version 4.7.0 patches the issue.4dCVE-2024-12616—26.4%
——8——CVE-2026-138258.8 HIG26.4%
——8Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)76dCVE-2020-8733—26.4%
——8——CVE-2025-23959—26.4%
——8——CVE-2026-24777—26.4%
——8——CVE-2026-138839.6 CRI26.4%
——8Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)76d