Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-3460—25.2%
——8——CVE-2026-24589—25.2%
——8——CVE-2024-32876—25.2%
——8——CVE-2026-27471—25.2%
——8——CVE-2024-31492—25.2%
——8——CVE-2025-54617—25.2%
——8——CVE-2024-438727.5 HIG25.2%
——8In the Linux kernel, the following vulnerability has been resolved:
RDMA/hns: Fix soft lockup under heavy CEQE load
CEQEs are handled in interrupt handler currently. This may cause the
CPU core staying in interrupt context too long and lead to soft lockup
under heavy load.
Handle CEQEs in BH workqueue and set an upper limit for the number of
CEQE handled by a single call of work handler.42dCVE-2026-3155—25.2%
——8——CVE-2022-47660—25.2%
——8——CVE-2026-53600—25.2%
——8async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g header) instead of to the next file entry. POSIX requires a PAX extended-header record set to describe the next file entry, never an intervening extension header. Because poll_next_raw (src/archive.rs) threads the buffered PAX records into the size computation of whatever raw header it reads next — and that header can be an intermediary L — the stream cursor is advanced by an attacker-chosen amount when the L body is consumed. The parser then desyncs relative to a POSIX-correct tar parser (e.g. GNU tar), reading subsequent bytes at the wrong block boundary. This issue has been patched in version 0.6.1.13dCVE-2022-0175—25.2%
——8——CVE-2024-11636—25.2%
——8——CVE-2021-1756—25.2%
——8——CVE-2024-4693—25.2%
——8——CVE-2025-14255—25.2%
——8——CVE-2026-22261—25.2%
——8——CVE-2024-25417—25.2%
——8——CVE-2023-45907—25.2%
——8——CVE-2020-0571—25.2%
——8——CVE-2019-14865—25.2%
——8——CVE-2026-191408.3 HIG25.2%
——8Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)39dCVE-1999-1372—25.2%
——8——CVE-2024-51541—25.2%
——8——CVE-2023-41810—25.2%
——8——CVE-2025-59683—25.2%
——8——CVE-2025-1921—25.2%
——8——CVE-2026-47171—25.2%
——8——CVE-2023-42571—25.2%
——8——CVE-2026-790305.3 MED25.2%
——8Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)20dCVE-2026-790285.3 MED25.2%
——8Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)19dCVE-2024-22592—25.2%
——8——CVE-2024-54223—25.2%
——8——CVE-2022-22686—25.2%
——8——CVE-2026-47172—25.2%
——8——CVE-2025-6345—25.2%
——8——CVE-2023-45906—25.2%
——8——CVE-2025-43862—25.2%
——8——CVE-2026-191558.3 HIG25.2%
——8Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)39dCVE-2025-68590—25.2%
——8——CVE-2026-6773—25.2%
——8——