Vulnerabilities exploitable today
372,926in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,236
- High8,261
- Medium6,234
- Low615
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-31075—23.9%
——7——CVE-2026-544988.7 HIG23.9%
——7view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied to normal #call return values. This creates an XSS risk when downstream applications use around_render to wrap, replace, instrument, or conditionally return content that includes user-controlled data, and ViewComponent::Collection#render_in can amplify the issue by joining per-item results and marking the entire output html_safe, converting raw unsafe output into an ActiveSupport::SafeBuffer. This issue is fixed in version 4.12.0.45dCVE-2026-91496.5 MED23.9%
——7A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).11dCVE-2024-38675—23.9%
——7——CVE-2022-46833—23.9%
——7——CVE-2025-66559—23.8%
——7——CVE-2023-22673—23.9%
——7——CVE-2026-71553—23.9%
——7ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared Object.prototype.toString function's call property and cause a persistent process-wide denial of service until restart.2dCVE-2026-22551—23.9%
——7——CVE-2025-41075—23.9%
——7——CVE-2026-110768.8 HIG23.9%
——7Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)51dCVE-2026-177474.2 MED23.9%
——7Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)40dCVE-2025-33079—23.9%
——7——CVE-2025-51867—23.9%
——7——CVE-2026-615188.8 HIG23.9%
——7ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection scanner does not block quote-free boolean payloads and does not reject requests in its default configuration. A remote API user holding any single low-privilege function permission can inject arbitrary SQL to delete or modify records across all tenants in the control panel database and extract arbitrary data via blind boolean inference, including password hashes and client records.23dCVE-2005-0715—23.9%
——7——CVE-2023-6990—23.9%
——7——CVE-2024-20906—23.9%
——7——CVE-2024-33926—23.9%
——7——CVE-2023-28995—23.9%
——7——CVE-2022-27581—23.9%
——7——CVE-2018-17400—23.9%
——7——CVE-2024-2166—23.9%
——7——CVE-2018-12172—23.9%
——7——CVE-2026-109528.8 HIG23.9%
——7Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)51dCVE-2025-4989—23.9%
——7——CVE-2012-0279—23.9%
——7——CVE-2023-5205—23.9%
——7——CVE-2026-770808.8 HIG23.9%
——7n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's file-access restrictions. An authenticated user with usable Snowflake credentials can upload a local file from the n8n host or overwrite an existing file with a staged one.10dCVE-2025-10909—23.9%
——7——CVE-2024-48293—23.9%
——7——CVE-2025-49536—23.9%
——7——CVE-2026-627985.5 MED23.9%
——7Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.29dCVE-2025-638957.5 HIG23.9%
——7An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted Link Manager Protocol (LMP) packet.69dCVE-2009-1753—23.9%
——7——CVE-2025-4990—23.9%
——7——CVE-2024-12808—23.8%
——7——CVE-2024-1663—23.8%
——7——CVE-2025-48383—23.8%
——7——CVE-2023-28173—23.8%
——7——