Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-43862—25.2%
——8——CVE-2026-48092—25.2%
——8——CVE-2026-24593—25.2%
——8——CVE-2026-6773—25.2%
——8——CVE-2025-68590—25.2%
——8——CVE-2025-1207—25.2%
——8——CVE-2023-45907—25.2%
——8——CVE-2026-34569—25.2%
——8——CVE-2024-13857—25.3%
——8——CVE-2025-25766—25.2%
——8——CVE-2026-89657.5 HIG25.2%
——8Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.54dCVE-2026-3155—25.2%
——8——CVE-2022-0175—25.3%
——8——CVE-2024-22593—25.2%
——8——CVE-2025-24173—25.2%
——8——CVE-2022-41664—25.2%
——8——CVE-2020-231365.5 MED25.3%
——8Microweber v1.1.18 is affected by no session expiry after log-out.69dCVE-2023-41811—25.3%
——8——CVE-2025-55213—25.2%
——8——CVE-2024-438727.5 HIG25.3%
——8In the Linux kernel, the following vulnerability has been resolved:
RDMA/hns: Fix soft lockup under heavy CEQE load
CEQEs are handled in interrupt handler currently. This may cause the
CPU core staying in interrupt context too long and lead to soft lockup
under heavy load.
Handle CEQEs in BH workqueue and set an upper limit for the number of
CEQE handled by a single call of work handler.42dCVE-2025-54617—25.2%
——8——CVE-2025-14254—25.3%
——8——CVE-2024-31492—25.3%
——8——CVE-2025-1145—25.2%
——8——CVE-2019-14865—25.3%
——8——CVE-2026-191408.3 HIG25.2%
——8Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)39dCVE-2019-9698—25.2%
——8——CVE-2025-29904—25.2%
——8——CVE-2026-35632—25.2%
——8——CVE-2026-3460—25.2%
——8——CVE-2026-191488.3 HIG25.2%
——8Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)38dCVE-2026-27471—25.2%
——8——CVE-2024-32876—25.3%
——8——CVE-2007-1500—25.3%
——8——CVE-2023-27632—25.3%
——8——CVE-2017-12699—25.3%
——8——CVE-2026-44328—25.2%
——8——CVE-2025-13770—25.3%
——8——CVE-2026-34945—25.2%
——8——CVE-2024-11636—25.2%
——8——