Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,213
- High8,121
- Medium6,188
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-32945—24.6%
——7——CVE-2026-178379.6 CRI24.6%
——7Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)40dCVE-2025-10185—24.6%
——7——CVE-2024-7011—24.6%
——7——CVE-2022-2657—24.6%
——7——CVE-2026-46684—24.6%
——7DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only token presence and length before userBOByToken(token) uses JWT.decode() without signature verification, allowing forged tokens with chosen uid and oid values to be accepted when licenseValid=true. This issue is fixed in version 2.10.23.57dCVE-2004-1066—24.6%
——7——CVE-2026-55237—24.6%
——7——CVE-2024-47782—24.6%
——7——CVE-2026-528318.0 HIG24.6%
——7Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, <command>). Two fields in the trigger specification flow into this string without adequate sanitization: event.headers keys and event.body. This issue has been patched in version 1.16.4.10dCVE-2025-14697—24.6%
——7——CVE-2006-6618—24.6%
——7——CVE-2026-843478.8 HIG24.6%
——7Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)10dCVE-2026-33129—24.6%
——7——CVE-2011-2145—24.6%
——7——CVE-2021-0124—24.6%
——7——CVE-2024-7251—24.6%
——7——CVE-2026-3739—24.6%
——7——CVE-2025-68002—24.6%
——7——CVE-2023-6195—24.6%
——7——CVE-2021-39780—24.6%
——7——CVE-2023-1697—24.6%
——7——CVE-2026-56027—24.6%
——7——CVE-2026-24390—24.6%
——7——CVE-2020-4492—24.6%
——7——CVE-2010-2376—24.6%
——7——CVE-2023-7012—24.6%
——7——CVE-2025-36752—24.6%
——7——CVE-2023-432325.4 MED24.6%
——7A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.66dCVE-2026-26362—24.6%
——7——CVE-2006-6623—24.6%
——7——CVE-2025-49549—24.6%
——7——CVE-2006-6621—24.6%
——7——CVE-2026-40562—24.6%
——7——CVE-2024-7252—24.6%
——7——CVE-2021-36234—24.6%
——7——CVE-2024-477218.8 HIG24.6%
——7In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw89: remove unused C2H event ID RTW89_MAC_C2H_FUNC_READ_WOW_CAM to prevent out-of-bounds reading
The handler of firmware C2H event RTW89_MAC_C2H_FUNC_READ_WOW_CAM isn't
implemented, but driver expects number of handlers is
NUM_OF_RTW89_MAC_C2H_FUNC_WOW causing out-of-bounds access. Fix it by
removing ID.
Addresses-Coverity-ID: 1598775 ("Out-of-bounds read")40dCVE-2026-8180—24.6%
——7——CVE-2026-28452—24.6%
——7——CVE-2026-34510—24.6%
——7——