Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-138038.3 HIG26.1%
——8Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)75dCVE-2026-41644—26.1%
——8——CVE-2019-25512—26.1%
——8——CVE-2026-29771—26.1%
——8——CVE-2023-53919—26.1%
——8——CVE-2024-29096—26.1%
——8——CVE-2024-28095—26.1%
——8——CVE-2026-8980—26.1%
——8——CVE-2023-2549—26.1%
——8——CVE-2025-4515—26.1%
——8——CVE-2025-24149—26.1%
——8——CVE-2026-33790—26.1%
——8——CVE-2024-30556—26.1%
——8——CVE-2022-43114.7 MED26.1%
——8
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This
could allow a user with access to the log files to discover connection strings of data sources configured for the
DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users
unauthorized access to the underlying data sources.
68dCVE-2005-1856—26.1%
——8——CVE-2025-3631—26.1%
——8——CVE-2025-1836—26.1%
——8——CVE-2024-29221—26.1%
——8——CVE-2024-0814—26.1%
——8——CVE-2025-0343—26.1%
——8——CVE-2026-144138.3 HIG26.1%
——8Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)75dCVE-2023-42926—26.1%
——8——CVE-2011-3164—26.1%
——8——CVE-2018-6472—26.1%
——8——CVE-2023-32092—26.1%
——8——CVE-2016-1456—26.1%
——8——CVE-2025-52513—26.1%
——8——CVE-2024-28188—26.1%
——8——CVE-2017-16948—26.1%
——8——CVE-2026-480997.1 HIG26.1%
——8WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.6dCVE-2024-41698—26.1%
——8——CVE-2018-6471—26.1%
——8——CVE-2026-470035.9 MED26.1%
——8Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).53dCVE-2017-16554—26.1%
——8——CVE-2020-23556—26.1%
——8——CVE-2026-554724.3 MED26.1%
——8Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This issue is fixed in version 8.6.2.64dCVE-1999-1318—26.1%
——8——CVE-2001-1091—26.1%
——8——CVE-2026-555456.5 MED26.1%
——8Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic without ObjectPrivilegeType.ReadPacket, ProcessingApi.subscribeAlgorithmStatus exposes the algorithm-status WebSocket topic without ObjectPrivilegeType.ReadAlgorithm, and MdbOverrideApi.subscribeMdbChanges exposes the mdb-changes WebSocket topic without SystemPrivilege.GetMissionDatabase. A low-privilege authenticated user can receive telemetry packets, algorithm status, and mission database change information outside the assigned authorization scope. This issue is fixed in versions 5.12.8 and 5.13.2.7dCVE-2019-25374—26.1%
——8——