Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,453
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-13579—26.3%
——8——CVE-2026-13531—26.3%
——8——CVE-2011-0702—26.3%
——8——CVE-2024-32535—26.3%
——8——CVE-2017-0349—26.3%
——8——CVE-2026-27100—26.3%
——8——CVE-2005-0515—26.3%
——8——CVE-2021-31225—26.3%
——8——CVE-2022-489608.8 HIG26.3%
——8In the Linux kernel, the following vulnerability has been resolved:
net: hisilicon: Fix potential use-after-free in hix5hd2_rx()
The skb is delivered to napi_gro_receive() which may free it, after
calling this, dereferencing skb may trigger use-after-free.43dCVE-2008-2329—26.3%
——8——CVE-2026-497837.8 HIG26.3%
——8Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.55dCVE-2026-586337.8 HIG26.3%
——8Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.62dCVE-2026-905256.3 MED26.3%
——8A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.1dCVE-2026-541157.8 HIG26.3%
——8Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.56dCVE-2009-3433—26.3%
——8——CVE-2026-504847.8 HIG26.3%
——8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.55dCVE-2007-4622—26.3%
——8——CVE-2026-135426.3 MED26.3%
——8A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /doctorprofile.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.77dCVE-2023-27417—26.3%
——8——CVE-2024-32541—26.3%
——8——CVE-2024-32545—26.3%
——8——CVE-2002-1518—26.3%
——8——CVE-2026-566507.8 HIG26.3%
——8Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.55dCVE-2007-1557—26.3%
——8——CVE-2019-6172—26.3%
——8——CVE-2006-0229—26.3%
——8——CVE-2021-21815—26.3%
——8——CVE-2003-1246—26.3%
——8——CVE-2025-4043—26.3%
——8——CVE-2008-1710—26.3%
——8——CVE-2026-586347.8 HIG26.3%
——8Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.62dCVE-2011-0729—26.3%
——8——CVE-2026-503317.8 HIG26.3%
——8Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.55dCVE-2026-147956.3 MED26.3%
——8A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/action-visitor.php. Such manipulation of the argument remark leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.71dCVE-2025-54832—26.3%
——8——CVE-2026-31851—26.3%
——8——CVE-2026-109788.8 HIG26.3%
——8Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)55dCVE-2026-53687.3 HIG26.3%
——8A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the argument uname causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.53dCVE-2026-3068—26.3%
——8——CVE-2026-665866.6 MED26.3%
——8Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.26d