Vulnerabilities exploitable today
369,447in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,103
- High7,551
- Medium5,625
- Low543
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-35120—21.1%
——6——CVE-2021-23882—21.1%
——6——CVE-2025-4098—21.1%
——6——CVE-2026-32098—21.1%
——6——CVE-2019-8742—21.1%
——6——CVE-2024-35737—21.1%
——6——CVE-2024-37097—21.1%
——6——CVE-2025-14056—21.1%
——6——CVE-2026-111168.8 HIG21.1%
——6Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)46dCVE-2024-56087—21.1%
——6——CVE-2023-46048—21.1%
——6——CVE-2026-75327.5 HIG21.1%
——6iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP address constraints.68dCVE-2018-12167—21.1%
——6——CVE-2017-14398—21.1%
——6——CVE-2024-37471—21.1%
——6——CVE-2024-29435—21.1%
——6——CVE-2024-35652—21.1%
——6——CVE-2024-49673—21.1%
——6——CVE-2019-8548—21.1%
——6——CVE-2024-41033—21.1%
——6——CVE-2025-46746—21.1%
——6——CVE-2024-45515—21.1%
——6——CVE-2024-37485—21.1%
——6——CVE-2022-49293—21.1%
——6——CVE-2026-748009.0 CRI21.1%
——6SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.12dCVE-2023-44141—21.1%
——6——CVE-2024-49651—21.1%
——6——CVE-2024-31403—21.1%
——6——CVE-2021-25351—21.1%
——6——CVE-2025-43827—21.1%
——6——CVE-2025-49183—21.1%
——6——CVE-2026-414458.8 HIG21.1%
——6KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr.c where the allocation size calculation dimOther*(dimReal+2)*sizeof(kiss_fft_scalar) overflows signed 32-bit integer arithmetic before being widened to size_t, causing malloc() to allocate an undersized buffer. Attackers can trigger heap buffer overflow by providing crafted dimensions that cause the multiplication to exceed INT_MAX, allowing writes beyond the allocated buffer region when kiss_fftndr() processes the data.55dCVE-2026-418558.1 HIG21.1%
——6In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.46dCVE-2024-49634—21.1%
——6——CVE-2024-35733—21.1%
——6——CVE-2026-258686.1 MED21.1%
——6MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the dir parameter. The application constructs $currentdir from user-controlled input and embeds it into an error message without output encoding, allowing an attacker to supply HTML/JavaScript that is reflected in the response. Successful exploitation can lead to execution of arbitrary script in a victim's browser in the context of the vulnerable application.55dCVE-2026-24583—21.1%
——6——CVE-2025-4040—21.1%
——6——CVE-2025-22063—21.1%
——6——CVE-2026-102786.3 MED21.1%
——6A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.ts of the component read_file/write_file. Executing a manipulation of the argument filePath/outputPath can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.47d