Vulnerabilities exploitable today
369,690in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,132
- High7,666
- Medium5,751
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-2364—21.7%
——7——CVE-2026-39111—21.7%
——7——CVE-2026-44570—21.7%
——7——CVE-2021-1863—21.7%
——7——CVE-2024-7539—21.7%
——7——CVE-2026-138736.5 MED21.7%
——7Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)69dCVE-2024-41125—21.7%
——7——CVE-2026-138096.5 MED21.7%
——7Side-channel information leakage in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)69dCVE-2025-14937—21.7%
——7——CVE-2026-26953—21.7%
——7——CVE-2012-0742—21.7%
——7——CVE-2025-55688—21.7%
——7——CVE-2026-168018.8 HIG21.7%
——7Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.41dCVE-2025-32917—21.7%
——7——CVE-2024-40916—21.7%
——7——CVE-2023-6672—21.7%
——7——CVE-2025-2975—21.7%
——7——CVE-2026-140696.5 MED21.7%
——7Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)69dCVE-2025-22261—21.7%
——7——CVE-2026-4304—21.7%
——7——CVE-2026-625083.1 LOW21.7%
——7Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).42dCVE-2025-0279—21.7%
——7——CVE-2026-426157.2 HIG21.7%
——7GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.46dCVE-2023-27441—21.7%
——7——CVE-2026-140966.5 MED21.7%
——7Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)69dCVE-2025-27149—21.7%
——7——CVE-2023-46277—21.7%
——7——CVE-2023-21481—21.7%
——7——CVE-2026-161464.9 MED21.7%
——7The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via Pattern JSON Keys/Values in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.19dCVE-2023-44220—21.7%
——7——CVE-2024-9471—21.7%
——7——CVE-2021-47105—21.7%
——7——CVE-2022-3432—21.7%
——7——CVE-2026-24468—21.7%
——7——CVE-2024-20256—21.7%
——7——CVE-2026-1789—21.7%
——7——CVE-2025-55691—21.7%
——7——CVE-2022-41680—21.7%
——7——CVE-2026-22602—21.7%
——7——CVE-2025-57483—21.7%
——7——