Vulnerabilities exploitable today
373,224in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,252
- High8,221
- Medium6,136
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-21818—25.0%
——7——CVE-2026-1078—25.0%
——7——CVE-2021-33463—25.0%
——7——CVE-2026-822348.2 HIG25.0%
——7SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time without validating the connect-time resolution. Attackers can use DNS rebinding to answer the guard resolution with a public IP and the connect resolution with a private or metadata IP, bypassing the SSRF defense to access cloud instance metadata and internal services.17dCVE-2025-31820—25.0%
——7——CVE-2026-544924.3 MED25.0%
——7Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view route accepts an authenticated user's private URL because app/Http/Requests/Subsonic/CreatePodcastChannelRequest.php does not apply the SafeUrl validation used by the regular podcast API. app/Http/Controllers/Subsonic/CreatePodcastChannelController.php passes the URL to app/Services/Podcast/PodcastService.php, where PodcastService::addPodcast() and createParser() invoke Poddle::fromUrl() during channel creation, causing immediate server-side requests to loopback, Docker bridge, or RFC1918 HTTP destinations. The confirmed impact is blind internal request execution because generic response-body exfiltration was not demonstrated through this route. This issue is fixed in version 9.7.0.5dCVE-2023-4948—25.0%
——7——CVE-2020-0508—25.0%
——7——CVE-2003-1008—25.0%
——7——CVE-2022-41995—25.0%
——7——CVE-2021-33465—25.0%
——7——CVE-2025-1801—25.0%
——7——CVE-2023-38626—25.0%
——7——CVE-2021-33464—25.0%
——7——CVE-2025-47490—25.0%
——7——CVE-2023-38625—25.0%
——7——CVE-2021-33461—25.0%
——7——CVE-2021-33466—25.0%
——7——CVE-2026-140086.5 MED25.0%
——7Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)75dCVE-2019-4236—25.0%
——7——CVE-2025-6195—25.0%
——7——CVE-2025-52752—25.0%
——7——CVE-2021-47703—25.0%
——7——CVE-2010-4248—25.0%
——7——CVE-2018-12434—24.9%
——7——CVE-2026-3368—25.0%
——7——CVE-2011-0542—25.0%
——7——CVE-2023-4455—25.0%
——7——CVE-2026-178489.6 CRI25.0%
——7Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)42dCVE-2008-6191—25.0%
——7——CVE-2026-20673—25.0%
——7——CVE-2021-33457—25.0%
——7——CVE-2026-27515—25.0%
——7——CVE-2025-10071—25.0%
——7——CVE-2023-22599—24.9%
——7——CVE-2025-12289—25.0%
——7——CVE-2026-577688.2 HIG25.0%
——7Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.63dCVE-2007-2729—25.0%
——7——CVE-2021-20268—25.0%
——7——CVE-2025-41728—25.0%
——7——