Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,276
- High8,382
- Medium6,420
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-30796—23.1%
——7——CVE-2025-30917—23.1%
——7——CVE-2025-30563—23.1%
——7——CVE-2024-10321—23.1%
——7——CVE-2026-138809.6 CRI23.1%
——7Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)71dCVE-2023-34144—23.1%
——7——CVE-2024-50547—23.1%
——7——CVE-2022-1744—23.1%
——7——CVE-2019-5248—23.1%
——7——CVE-2025-43003—23.1%
——7——CVE-2026-2350—23.1%
——7——CVE-2025-12242—23.1%
——7——CVE-2026-8540—23.1%
——7——CVE-2020-3959—23.1%
——7——CVE-2025-26996—23.1%
——7——CVE-2025-138729.1 CRI23.1%
——7Blind Server-Side Request Forgery (SSRF) in the survey-import feature of
ObjectPlanet Opinio 7.26 rev12562 on
Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests
to an arbitrary destination.8dCVE-2025-22570—23.1%
——7——CVE-2026-826294.7 MED23.1%
——7A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This issue affects the function MyJwWebJwid3Controller.doUpload of the file jeewx-boot-module-weixin/src/main/java/com/jeecg/p3/open/web/back/MyJwWebJwid3Controller.java of the component doUpload Endpoint. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.11dCVE-2026-0114—23.1%
——7——CVE-2025-30614—23.1%
——7——CVE-2024-47592—23.1%
——7——CVE-2023-6253—23.1%
——7——CVE-2025-30798—23.1%
——7——CVE-2025-53901—23.1%
——7——CVE-2026-0113—23.1%
——7——CVE-2020-3427—23.1%
——7——CVE-2025-30827—23.1%
——7——CVE-2026-66844.6 MED23.1%
——7FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.71dCVE-2025-30869—23.1%
——7——CVE-2025-24730—23.1%
——7——CVE-2025-30547—23.1%
——7——CVE-2020-5988—23.1%
——7——CVE-2026-763656.5 MED23.1%
——7In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database through custom list retrieval in a playbook, allowing for create, read, update, and delete operations on all relevant data stored in the Splunk SOAR database. The SQL injection is possible because Splunk SOAR builds the custom list database lookup with the supplied list name instead of a bound SQL value. For more information see Manage roles and permissions in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-cloud) and Create custom lists for use in Splunk SOAR playbook comparisons (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/create-custom-lists-for-use-in-splunk-soar-cloud-playbook-comparisons) in the Splunk documentation.21dCVE-2023-34145—23.1%
——7——CVE-2026-0116—23.1%
——7——CVE-2026-141139.6 CRI23.1%
——7Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)71dCVE-2023-34182—23.1%
——7——CVE-2026-161224.3 MED23.1%
——7A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit has been released to the public and may be used for attacks.53dCVE-2025-30840—23.1%
——7——CVE-2025-30559—23.1%
——7——