Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,276
- High8,382
- Medium6,420
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-18826—23.1%
——7——CVE-2024-40514—23.1%
——7——CVE-2025-12254—23.1%
——7——CVE-2026-138809.6 CRI23.1%
——7Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)71dCVE-2026-32319—23.1%
——7——CVE-2026-39534—23.1%
——7——CVE-2025-5702—23.1%
——7——CVE-2024-45391—23.1%
——7——CVE-2025-30837—23.1%
——7——CVE-2025-12252—23.1%
——7——CVE-2024-12463—23.1%
——7——CVE-2025-30902—23.1%
——7——CVE-2026-24811—23.1%
——7——CVE-2025-13579—23.1%
——7——CVE-2023-34178—23.1%
——7——CVE-2025-13580—23.1%
——7——CVE-2026-161224.3 MED23.1%
——7A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit has been released to the public and may be used for attacks.53dCVE-2025-30559—23.1%
——7——CVE-2025-30796—23.1%
——7——CVE-2025-30563—23.1%
——7——CVE-2024-10321—23.1%
——7——CVE-2026-0116—23.1%
——7——CVE-2024-47592—23.1%
——7——CVE-2023-6253—23.1%
——7——CVE-2023-34145—23.1%
——7——CVE-2025-53901—23.1%
——7——CVE-2026-0114—23.1%
——7——CVE-2025-138729.1 CRI23.1%
——7Blind Server-Side Request Forgery (SSRF) in the survey-import feature of
ObjectPlanet Opinio 7.26 rev12562 on
Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests
to an arbitrary destination.8dCVE-2025-30614—23.1%
——7——CVE-2026-826294.7 MED23.1%
——7A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This issue affects the function MyJwWebJwid3Controller.doUpload of the file jeewx-boot-module-weixin/src/main/java/com/jeecg/p3/open/web/back/MyJwWebJwid3Controller.java of the component doUpload Endpoint. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.11dCVE-2025-30798—23.1%
——7——CVE-2025-26996—23.1%
——7——CVE-2020-3427—23.1%
——7——CVE-2026-66844.6 MED23.1%
——7FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.71dCVE-2025-30917—23.1%
——7——CVE-2026-0113—23.1%
——7——CVE-2025-24730—23.1%
——7——CVE-2025-30544—23.1%
——7——CVE-2025-30869—23.1%
——7——CVE-2024-13599—23.1%
——7——