Vulnerabilities exploitable today
369,392in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,099
- High7,540
- Medium5,594
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-754177.2 HIG20.8%
——6A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated directly into a FIND_IN_SET() SQL clause without proper sanitization. This allows an authenticated administrator to execute arbitrary SQL queries via boolean-based blind injection, potentially leading to full database compromise.4dCVE-2024-35240—20.8%
——6——CVE-2024-11021—20.8%
——6——CVE-2026-7109—20.8%
——6——CVE-2026-170708.8 HIG20.8%
——6Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Liman MYS: from 2.2.3 before 2.3.1.12dCVE-2026-109007.5 HIG20.8%
——6Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)46dCVE-2024-33948—20.8%
——6——CVE-2026-108997.5 HIG20.8%
——6Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)46dCVE-2023-32556—20.8%
——6——CVE-2026-109088.3 HIG20.8%
——6Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)46dCVE-2026-737028.8 HIG20.8%
——6A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise.5dCVE-2020-8016—20.8%
——6——CVE-2026-109258.3 HIG20.8%
——6Out of bounds write in Skia in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)46dCVE-2025-29710—20.8%
——6——CVE-2025-14911—20.8%
——6——CVE-2026-109188.3 HIG20.8%
——6Use after free in Viz in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)46dCVE-2020-14477—20.8%
——6——CVE-2026-136138.8 HIG20.8%
——6The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.12dCVE-2024-44716—20.8%
——6——CVE-2025-31333—20.8%
——6——CVE-2025-6849—20.8%
——6——CVE-2024-53784—20.8%
——6——CVE-2025-32407—20.8%
——6——CVE-2025-27810—20.8%
——6——CVE-2025-14039—20.8%
——6——CVE-2026-8628—20.8%
——6——CVE-2026-109538.3 HIG20.8%
——6Use after free in Core in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)46dCVE-2024-56272—20.8%
——6——CVE-2024-33803—20.8%
——6——CVE-2026-108948.3 HIG20.8%
——6Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)46dCVE-2025-59784—20.8%
——6——CVE-2025-29986—20.8%
——6——CVE-2025-1271—20.8%
——6——CVE-2025-27822—20.8%
——6——CVE-2025-58325—20.8%
——6——CVE-2026-569683.7 LOW20.8%
——6GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.38dCVE-2026-4314—20.8%
——6——CVE-2025-65030—20.8%
——6——CVE-2025-57539—20.8%
——6——CVE-2024-46919—20.8%
——6——