Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-0497—25.6%
——8——CVE-2024-5545—25.6%
——8——CVE-2024-44215—25.6%
——8——CVE-2024-37222—25.6%
——8——CVE-2013-0349—25.6%
——8——CVE-2023-29761—25.6%
——8——CVE-2023-29758—25.6%
——8——CVE-2025-27802—25.6%
——8——CVE-2026-71391—25.6%
——8GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison instead of greater-than-or-equal, allowing a crafted TrueType variable font to bypass the check and trigger a heap-based out-of-bounds read via memcpy. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This exposes heap memory contents which can be later used to defeat ASLR.
This issue was fixed in commit 95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe18dCVE-2025-40660—25.6%
——8——CVE-2006-5394—25.6%
——8——CVE-2024-26798—25.6%
——8——CVE-2019-25496—25.6%
——8——CVE-2025-26374—25.6%
——8——CVE-2017-202818.2 HIG25.6%
——8Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malicious SQL in the establename field to extract sensitive database information.27dCVE-2024-8658—25.6%
——8——CVE-2013-4829—25.6%
——8——CVE-2021-33889—25.6%
——8——CVE-2024-10566—25.6%
——8——CVE-2019-25495—25.6%
——8——CVE-2024-7326—25.6%
——8——CVE-2023-50953—25.6%
——8——CVE-2026-138198.1 HIG25.6%
——8Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)75dCVE-2022-43281—25.6%
——8——CVE-2023-73033.5 LOW25.6%
——8A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This affects the function process_request of the file q2apro-onsitenotifications-page.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.4.8 is able to address this issue. The patch is named 0ca85ca02f8aceb661e9b71fd229c45d388ea5b5. It is recommended to upgrade the affected component.13dCVE-2024-51099—25.6%
——8——CVE-2008-0585—25.6%
——8——CVE-2007-3381—25.6%
——8——CVE-2021-3602—25.6%
——8——CVE-2025-40658—25.6%
——8——CVE-1999-0327—25.6%
——8——CVE-2013-7336—25.6%
——8——CVE-2026-24984—25.6%
——8——CVE-2008-3973—25.6%
——8——CVE-2026-8463—25.6%
——8——CVE-2024-35696—25.6%
——8——CVE-2024-1097—25.6%
——8——CVE-2025-62290—25.6%
——8——CVE-2019-25497—25.6%
——8——CVE-2023-295496.5 MED25.6%
——8Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.27d