Vulnerabilities exploitable today
372,253in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,277
- High8,394
- Medium6,440
- Low634
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2011-1307—23.1%
——7——CVE-2026-692885.5 MED23.1%
——7Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.2dCVE-2026-697317.8 HIG23.1%
——7Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally.2dCVE-2026-140196.5 MED23.1%
——7Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)72dCVE-2019-25509—23.1%
——7——CVE-2024-1217—23.1%
——7——CVE-2026-141556.5 MED23.1%
——7Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)71dCVE-2024-52486—23.1%
——7——CVE-2023-40424—23.1%
——7——CVE-2018-21096—23.1%
——7——CVE-2024-29950—23.1%
——7——CVE-2024-438818.8 HIG23.1%
——7In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: change DMA direction while mapping reinjected packets
For fragmented packets, ath12k reassembles each fragment as a normal
packet and then reinjects it into HW ring. In this case, the DMA
direction should be DMA_TO_DEVICE, not DMA_FROM_DEVICE. Otherwise,
an invalid payload may be reinjected into the HW and
subsequently delivered to the host.
Given that arbitrary memory can be allocated to the skb buffer,
knowledge about the data contained in the reinjected buffer is lacking.
Consequently, there’s a risk of private information being leaked.
Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00209-QCAHKSWPL_SILICONZ-138dCVE-2023-37342—23.1%
——7——CVE-2026-29055—23.1%
——7——CVE-2026-32742—23.1%
——7——CVE-2025-3615—23.1%
——7——CVE-2025-21085—23.1%
——7——CVE-2025-53608—23.1%
——7——CVE-2024-39599—23.1%
——7——CVE-2025-47991—23.1%
——7——CVE-2026-46719—23.1%
——7——CVE-2022-262507.8 HIG23.1%
——7Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.64dCVE-2025-31858—23.1%
——7——CVE-2020-36558—23.1%
——7——CVE-2025-54869—23.1%
——7——CVE-2024-12809—23.1%
——7——CVE-2024-12620—23.1%
——7——CVE-2024-11321—23.1%
——7——CVE-2018-4032—23.1%
——7——CVE-2026-625105.3 MED23.1%
——7Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).16dCVE-2024-52035—23.1%
——7——CVE-2024-43163—23.1%
——7——CVE-2026-738955.3 MED23.1%
——7Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).13dCVE-2020-19268—23.1%
——7——CVE-2011-2292—23.1%
——7——CVE-2025-3814—23.1%
——7——CVE-2024-54028—23.1%
——7——CVE-2016-8462—23.1%
——7——CVE-2026-51244—23.1%
——7Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.42dCVE-2024-235674.3 MED23.1%
——7HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.56d