Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-39154—21.9%
——7——CVE-2025-41682—21.9%
——7——CVE-2026-109506.5 MED21.9%
——7Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)48dCVE-2022-35279—21.9%
——7——CVE-2017-8391—21.9%
——7——CVE-2023-21405—21.9%
——7——CVE-2026-726446.5 MED21.9%
——7Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit a specially crafted request that produces an unhandled error condition, terminating the Kibana process and denying service to all users and spaces on that instance until it is restarted.6dCVE-2025-53455—21.9%
——7——CVE-2024-4199—21.9%
——7——CVE-2026-99958.8 HIG21.9%
——7Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)50dCVE-2026-227476.8 MED21.9%
——7Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
This issue affects Spring Security: from 7.0.0 through 7.0.4.56dCVE-2026-593206.5 MED21.9%
——7When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and the broker stops delivering, leaving the listener silently stalled while isRunning() remains true.
Spring AMQP 4.1.08dCVE-2025-55049—21.9%
——7——CVE-2025-63662—21.9%
——7——CVE-2024-421337.6 HIG21.9%
——7In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: Ignore too large handle values in BIG
hci_le_big_sync_established_evt is necessary to filter out cases where the
handle value is belonging to ida id range, otherwise ida will be erroneously
released in hci_conn_cleanup.36dCVE-2025-556586.5 MED21.9%
——7GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media_tools/av_parsers.c). bThis vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.48dCVE-2018-19441—21.9%
——7——CVE-2021-32000—21.9%
——7——CVE-2026-99768.8 HIG21.9%
——7Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)50dCVE-2021-22573—21.9%
——7——CVE-2025-8942—21.9%
——7——CVE-2025-27298—21.9%
——7——CVE-2025-31544—21.9%
——7——CVE-2024-44032—21.9%
——7——CVE-2021-23827—21.9%
——7——CVE-2024-39158—21.9%
——7——CVE-2023-45181—21.9%
——7——CVE-2026-663968.4 HIG21.9%
——7SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron renderer with full Node.js access when victims open affected documents.42dCVE-2025-53460—21.9%
——7——CVE-2026-630956.5 MED21.9%
——7Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership verification. Attackers can exploit the unverified Forget3PID handler to remove a victim's email or MSISDN binding and subsequently rebind the address through an identity server to hijack the victim's password reset flow.53dCVE-2026-726526.5 MED21.9%
——7Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable.6dCVE-2008-0217—21.9%
——7——CVE-2025-36247—21.9%
——7——CVE-2025-48445—21.9%
——7——CVE-2022-21230—21.9%
——7——CVE-2026-667587.8 HIG21.9%
——7A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.7dCVE-2024-9683—21.9%
——7——CVE-2026-32483—21.9%
——7——CVE-2026-28917—21.9%
——7——CVE-2025-3478—21.9%
——7——