Vulnerabilities exploitable today
372,926in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,236
- High8,261
- Medium6,234
- Low615
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-25202—23.9%
——7——CVE-2026-30848—23.9%
——7——CVE-2026-241657.8 HIG23.9%
——7NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.49dCVE-2024-51875—23.9%
——7——CVE-2025-69443—23.9%
——7——CVE-2025-26588—23.9%
——7——CVE-2026-627865.5 MED23.9%
——7Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.26dCVE-2023-24395—23.9%
——7——CVE-2023-46641—23.9%
——7——CVE-2010-5171—23.9%
——7——CVE-2024-0911—23.9%
——7——CVE-2022-46834—23.9%
——7——CVE-2023-23993—23.9%
——7——CVE-2023-33802—23.8%
——7——CVE-2024-5627—23.8%
——7——CVE-2025-10532—23.9%
——7——CVE-2024-48913—23.9%
——7——CVE-2025-27269—23.9%
——7——CVE-2020-3201—23.9%
——7——CVE-2025-47096—23.9%
——7——CVE-2025-1933—23.9%
——7——CVE-2024-56359—23.9%
——7——CVE-2026-71553—23.9%
——7ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared Object.prototype.toString function's call property and cause a persistent process-wide denial of service until restart.2dCVE-2023-31075—23.9%
——7——CVE-2024-11491—23.9%
——7——CVE-2026-627965.5 MED23.9%
——7Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.26dCVE-2024-29104—23.9%
——7——CVE-2023-0737—23.9%
——7——CVE-2026-656625.5 MED23.9%
——7Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.26dCVE-2026-627935.5 MED23.9%
——7Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.26dCVE-2026-110768.8 HIG23.9%
——7Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)51dCVE-2026-177474.2 MED23.9%
——7Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)40dCVE-2025-4990—23.9%
——7——CVE-2009-1753—23.9%
——7——CVE-2025-638957.5 HIG23.9%
——7An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted Link Manager Protocol (LMP) packet.69dCVE-2022-46833—23.9%
——7——CVE-2026-91496.5 MED23.9%
——7A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).11dCVE-2026-544988.7 HIG23.9%
——7view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied to normal #call return values. This creates an XSS risk when downstream applications use around_render to wrap, replace, instrument, or conditionally return content that includes user-controlled data, and ViewComponent::Collection#render_in can amplify the issue by joining per-item results and marking the entire output html_safe, converting raw unsafe output into an ActiveSupport::SafeBuffer. This issue is fixed in version 4.12.0.45dCVE-2026-42350—23.9%
——7Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Kargo is vulnerable to open redirect in UI OIDC login flow via the redirectTo query parameter. This issue has been patched in versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2.49dCVE-2025-66559—23.8%
——7——