Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-10118—25.4%
——8——CVE-2025-1013—25.4%
——8——CVE-2026-14550—25.4%
——8——CVE-2022-1404—25.4%
——8——CVE-2020-35804—25.4%
——8——CVE-2026-208447.4 HIG25.4%
——8Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.47dCVE-2024-11627—25.4%
——8——CVE-2026-34354—25.4%
——8——CVE-2024-43793—25.4%
——8——CVE-2026-812695.3 MED25.4%
——8Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.6dCVE-2019-3652—25.4%
——8——CVE-2026-24287—25.4%
——8——CVE-2025-4152—25.4%
——8——CVE-2024-13056—25.4%
——8——CVE-2024-10718—25.4%
——8——CVE-2024-50354—25.4%
——8——CVE-2026-628047.8 HIG25.4%
——8External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.7dCVE-2020-4102—25.4%
——8——CVE-2024-57957—25.4%
——8——CVE-2026-26936—25.4%
——8——CVE-2024-51860—25.4%
——8——CVE-2024-51885—25.4%
——8——CVE-2024-51908—25.4%
——8——CVE-2020-15852—25.4%
——8——CVE-2025-57751—25.4%
——8——CVE-2021-0145—25.4%
——8——CVE-2026-146863.3 LOW25.4%
——8A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range Check. Performing a manipulation results in incorrect comparison. The attack is only possible with local access. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.61dCVE-2024-49824—25.4%
——8——CVE-2024-39495—25.4%
——8——CVE-2025-49564—25.4%
——8——CVE-2025-1187—25.4%
——8——CVE-2026-654366.8 MED25.4%
——8Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.50dCVE-2026-455427.1 HIG25.4%
——8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase handler (handle_session_command0() in components/protocomm/src/security/security2.c) trusts the length of a client-supplied protobuf field for the SRP6a username and copies it into a buffer whose size is derived from a narrower destination type. The resulting truncation-versus-copy asymmetry corrupts the heap when an oversized value is supplied. This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.54dCVE-2024-3821—25.4%
——8——CVE-2025-27161—25.4%
——8——CVE-2021-35954—25.4%
——8——CVE-2005-3527—25.4%
——8——CVE-2025-35041—25.4%
——8——CVE-2025-58160—25.4%
——8——CVE-2022-44741—25.4%
——8——