Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,220
- High8,140
- Medium6,165
- Low607
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-4630—22.9%
——7——CVE-2025-49403—22.9%
——7——CVE-2026-149739.3 CRI22.9%
——7IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.28dCVE-2024-52534—22.9%
——7——CVE-2023-37525—22.9%
——7——CVE-2024-41228—22.9%
——7——CVE-2025-14385—22.9%
——7——CVE-2025-65408—22.9%
——7——CVE-2023-52650—22.9%
——7——CVE-2022-1787—22.9%
——7——CVE-2024-49527—22.9%
——7——CVE-2025-30196—22.9%
——7——CVE-2022-1818—22.9%
——7——CVE-2026-151208.3 HIG22.9%
——7Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)63dCVE-2024-2965—22.9%
——7——CVE-2025-53620—22.9%
——7——CVE-2026-44555—22.9%
——7——CVE-2024-9781—22.9%
——7——CVE-2017-20195—22.9%
——7——CVE-2026-45565—22.9%
——7——CVE-2026-28442—22.9%
——7——CVE-2026-530869.8 CRI22.9%
——7In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: fix racing timeout handler
The bcmgenet_timeout handler tries to take down all tx queues when
a single queue times out. This is over zealous and causes many race
conditions with queues that are still chugging along. Instead lets
only restart the timed out queue.49dCVE-2025-64086—22.9%
——7——CVE-2023-28694—22.9%
——7——CVE-2024-5867—22.9%
——7——CVE-2026-749428.8 HIG22.9%
——7Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.21dCVE-2024-0771—22.9%
——7——CVE-2018-7944—22.9%
——7——CVE-2022-1780—22.9%
——7——CVE-2026-139518.3 HIG22.9%
——7Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)70dCVE-2026-138018.3 HIG22.9%
——7Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)71dCVE-2026-835937.2 HIG22.9%
——7The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The action is gated only by a nonce that is localized into every public-facing page via wp_localize_script, rendering the nonce check ineffective as an access control barrier for unauthenticated users.1dCVE-2026-21879—22.9%
——7——CVE-2025-20703—22.9%
——7——CVE-2026-39533—22.9%
——7——CVE-2026-138418.3 HIG22.9%
——7Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)70dCVE-2024-39735—22.9%
——7——CVE-2022-240307.5 HIG22.9%
——7An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.30dCVE-2026-28907—22.9%
——7——CVE-2025-13739—22.9%
——7——