Vulnerabilities exploitable today
373,224in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,252
- High8,221
- Medium6,136
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-29908—24.8%
——7——CVE-2025-31923—24.8%
——7——CVE-2024-32556—24.8%
——7——CVE-2025-3422—24.8%
——7——CVE-2025-7856—24.8%
——7——CVE-2024-11485—24.8%
——7——CVE-2026-8208—24.8%
——7Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the underlying web server.52dCVE-2025-47526—24.8%
——7——CVE-2025-3157—24.8%
——7——CVE-2024-32697—24.8%
——7——CVE-2026-40815—24.8%
——7——CVE-2025-28985—24.8%
——7——CVE-2024-26482—24.8%
——7——CVE-2026-32070—24.8%
——7——CVE-2026-54079—24.8%
——7veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/impl/pd/GFPDAcroForm.java in the getdynamicRender() method, where a crafted PDF containing a malicious XFA stream can cause external entity expansion during PDF/UA-1 validation and allow local file disclosure or outbound server-side requests. This issue is fixed in versions 1.30.2 and 1.31.71.46dCVE-2026-40816—24.8%
——7——CVE-2026-40819—24.8%
——7——CVE-2026-176157.5 HIG24.8%
——7A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.3dCVE-2025-27261—24.8%
——7——CVE-2025-55228—24.8%
——7——CVE-2021-35599—24.8%
——7——CVE-2026-591355.5 MED24.8%
——7Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.29dCVE-2026-24729—24.8%
——7——CVE-2024-32536—24.8%
——7——CVE-2026-7146—24.8%
——7——CVE-2022-42830—24.8%
——7——CVE-2024-2580—24.8%
——7——CVE-2026-40811—24.8%
——7——CVE-2023-21220—24.8%
——7——CVE-2025-27405—24.8%
——7——CVE-2026-40818—24.8%
——7——CVE-2026-137859.6 CRI24.8%
——7Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)74dCVE-2023-44117—24.8%
——7——CVE-2023-33006—24.8%
——7——CVE-2026-34364—24.8%
——7——CVE-2026-137778.8 HIG24.8%
——7Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)74dCVE-2026-50019—24.8%
——7——CVE-2026-30970—24.8%
——7——CVE-2026-21530—24.8%
——7——CVE-2022-45586—24.8%
——7——