Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,286
- High8,401
- Medium6,423
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-11715—23.0%
——7——CVE-2020-12702—23.0%
——7——CVE-2026-6592—23.0%
——7——CVE-2026-1722—23.0%
——7——CVE-2023-46203—23.0%
——7——CVE-2024-32713—23.0%
——7——CVE-2025-712567.5 HIG23.0%
——7In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.48dCVE-2023-28016—23.0%
——7——CVE-2025-2335—23.0%
——7——CVE-2019-15743—23.0%
——7——CVE-2007-5042—23.0%
——7——CVE-2007-5041—23.0%
——7——CVE-2025-7698—23.0%
——7——CVE-2025-712517.5 HIG23.0%
——7In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.48dCVE-2008-1132—23.0%
——7——CVE-2026-789084.3 MED23.0%
——7Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)14dCVE-2017-9677—23.0%
——7——CVE-2019-15474—23.0%
——7——CVE-2019-15471—23.0%
——7——CVE-2026-536666.1 MED23.0%
——7React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0.39dCVE-2025-57954—23.0%
——7——CVE-2025-54838—23.0%
——7——CVE-2015-5013—23.0%
——7——CVE-2026-588229.8 CRI23.0%
——7In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.2dCVE-2010-2400—23.0%
——7——CVE-2024-5142—23.0%
——7——CVE-2025-42876—23.0%
——7——CVE-2014-6881—23.0%
——7——CVE-2026-489126.5 MED23.0%
——7Improper Input Validation vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs.
Users are recommended to upgrade to version 2.0.2, which fixes the issue.35dCVE-2026-109118.3 HIG23.0%
——7Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)50dCVE-2024-7713—23.0%
——7——CVE-2022-1591—23.0%
——7——CVE-2026-742455.9 MED23.0%
——7A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure, potentially exposing sensitive data such as usernames, email addresses, IP addresses, and action-specific metadata.21dCVE-2007-4564—23.0%
——7——CVE-2025-58746—23.0%
——7——CVE-2025-57964—23.0%
——7——CVE-2026-712878.8 HIG23.0%
——7Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as passes through completely unmodified.15dCVE-2026-23972—23.0%
——7——CVE-2026-109208.3 HIG23.0%
——7Insufficient validation of untrusted input in WebShare in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)50dCVE-2024-31980—23.0%
——7——