Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,222
- High8,205
- Medium6,238
- Low607
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2005-1066—22.8%
——7——CVE-2026-649087.8 HIG22.8%
——7Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.27dCVE-2026-8779—22.8%
——7——CVE-2000-0959—22.8%
——7——CVE-2013-1610—22.8%
——7——CVE-2023-44464—22.8%
——7——CVE-2010-2619—22.8%
——7——CVE-2025-5297—22.8%
——7——CVE-2025-67482—22.8%
——7——CVE-2020-4791—22.8%
——7——CVE-2013-0403—22.8%
——7——CVE-2011-4363—22.8%
——7——CVE-2025-11165—22.8%
——7——CVE-2026-635337.8 HIG22.8%
——7Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.27dCVE-2025-3285—22.8%
——7——CVE-2026-31884—22.8%
——7——CVE-2019-8579—22.8%
——7——CVE-2025-62413—22.8%
——7——CVE-2024-12465—22.8%
——7——CVE-2026-179188.8 HIG22.8%
——7Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)38dCVE-2023-29067—22.8%
——7——CVE-2026-58798.8 HIG22.8%
——7Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)48dCVE-2017-8185—22.8%
——7——CVE-2019-5527—22.8%
——7——CVE-2025-2286—22.8%
——7——CVE-2024-51900—22.8%
——7——CVE-2011-4144—22.8%
——7——CVE-2025-61457—22.8%
——7——CVE-2026-95715.9 MED22.8%
——7Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-0068058dCVE-2010-3244—22.8%
——7——CVE-2026-58778.8 HIG22.8%
——7Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)48dCVE-2023-2717—22.8%
——7——CVE-2020-27830—22.8%
——7——CVE-2026-141829.8 CRI22.8%
——7The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.15dCVE-2025-1672—22.8%
——7——CVE-2019-11836—22.8%
——7——CVE-2025-2293—22.8%
——7——CVE-2025-3286—22.8%
——7——CVE-2024-40875—22.8%
——7——CVE-2026-58618.8 HIG22.8%
——7Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)48d