Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,213
- High8,121
- Medium6,188
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-41088—24.6%
——7——CVE-2016-7620—24.6%
——7——CVE-2026-768868.1 HIG24.6%
——7C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service15dCVE-2026-100138.8 HIG24.6%
——7Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)54dCVE-2016-8774—24.6%
——7——CVE-2025-58095—24.6%
——7——CVE-2026-2490—24.6%
——7——CVE-2024-55891—24.6%
——7——CVE-2025-45586—24.6%
——7——CVE-2025-54761—24.6%
——7——CVE-2019-25451—24.6%
——7——CVE-2020-4382—24.6%
——7——CVE-2006-1166—24.6%
——7——CVE-2023-47081—24.6%
——7——CVE-2018-3661—24.6%
——7——CVE-2019-4298—24.6%
——7——CVE-2026-44257—24.6%
——7——CVE-2014-4225—24.6%
——7——CVE-2024-47097—24.6%
——7——CVE-2025-12285—24.6%
——7——CVE-2025-9241—24.6%
——7——CVE-2014-7251—24.6%
——7——CVE-2025-2544—24.6%
——7——CVE-2026-735606.5 MED24.6%
——7vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through _fetch_image, requests.get, and Image.open instead of MediaConnector, bypassing allowed_media_domains and allowed_local_media_path protections and allowing server-side requests and reads of arbitrary files accessible to the vLLM process. This issue is fixed in version 0.26.0.26dCVE-2025-2836—24.6%
——7——CVE-2025-8938—24.6%
——7——CVE-2025-54474—24.6%
——7——CVE-2026-95287.3 HIG24.6%
——7A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.52dCVE-2012-5303—24.6%
——7——CVE-2024-21961—24.6%
——7——CVE-2024-12597—24.6%
——7——CVE-2023-48636—24.6%
——7——CVE-2022-35867—24.6%
——7——CVE-2026-21530—24.6%
——7——CVE-2024-38351—24.6%
——7——CVE-2026-95257.3 HIG24.6%
——7A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument judge_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.52dCVE-2025-48929—24.6%
——7——CVE-2008-4993—24.6%
——7——CVE-2026-672135.9 MED24.6%
——7nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.26dCVE-2026-56401—24.6%
——7Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.60d