Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,213
- High8,121
- Medium6,188
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-31931—24.6%
——7——CVE-2020-8482—24.6%
——7——CVE-2021-24388—24.6%
——7——CVE-2025-62701—24.6%
——7——CVE-2026-157786.5 MED24.6%
——7Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)60dCVE-2024-51720—24.6%
——7——CVE-2026-151148.8 HIG24.6%
——7Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)65dCVE-2025-65289—24.6%
——7——CVE-2024-31927—24.6%
——7——CVE-2026-476177.5 HIG24.6%
——7NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.37dCVE-2025-52566—24.6%
——7——CVE-2024-31361—24.6%
——7——CVE-2026-811683.7 LOW24.6%
——7Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.3dCVE-2026-672437.2 HIG24.6%
——7freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.16dCVE-2023-47714—24.6%
——7——CVE-2026-737048.8 HIG24.6%
——7A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete compromise of the affected system.11dCVE-2026-36236—24.6%
——7——CVE-2026-29861—24.6%
——7——CVE-2024-6971—24.6%
——7——CVE-2026-456805.9 MED24.6%
——7OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations by looping once per recorded run count. On busy systems, the run-count delta can become very large, causing the metrics exporter to spend excessive CPU time in a tight loop every collection interval. This issue has been patched in version 0.9.0.52dCVE-2026-476187.5 HIG24.6%
——7NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.37dCVE-2026-476167.5 HIG24.6%
——7NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.36dCVE-2026-476137.5 HIG24.6%
——7NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.36dCVE-2026-29204—24.6%
——7——CVE-2025-62693—24.6%
——7——CVE-2026-28399—24.6%
——7——CVE-2026-26708—24.6%
——7——CVE-2023-41881—24.6%
——7——CVE-2026-470606.5 MED24.6%
——7Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise JDBC. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JDBC accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).38dCVE-2023-31142—24.6%
——7——CVE-2026-697387.8 HIG24.6%
——7Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.4dCVE-2024-40604—24.6%
——7——CVE-2025-15507—24.6%
——7——CVE-2012-4089—24.6%
——7——CVE-2026-169287.5 HIG24.6%
——7IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow.19dCVE-2026-353863.6 LOW24.6%
——7In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.50dCVE-2025-12612—24.6%
——7——CVE-2024-32080—24.6%
——7——CVE-2018-15332—24.6%
——7——CVE-2017-2384—24.6%
——7——