Vulnerabilities exploitable today
369,346in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,105
- High7,541
- Medium5,577
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-15357—20.7%
——6——CVE-2019-15353—20.7%
——6——CVE-2026-23928—20.7%
——6——CVE-2026-42891—20.7%
——6——CVE-2026-41166—20.7%
——6——CVE-2025-49907—20.7%
——6——CVE-2026-110456.5 MED20.7%
——6Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)46dCVE-2025-33133—20.7%
——6——CVE-2026-554025.9 MED20.7%
——6CVE-2026-55402 is an out of bounds read vulnerability in Secure Access
servers prior to version 14.57. Attackers with an ‘in the middle’
position can send specially crafted data to a server causing a
persistent denial of service.2dCVE-2024-36457—20.7%
——6——CVE-2024-11276—20.7%
——6——CVE-2022-2405—20.7%
——6——CVE-2026-143649.8 CRI20.7%
——6The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible for unauthenticated attackers to reset the password of arbitrary user accounts, including administrators, and gain access to those accounts.25dCVE-2025-33126—20.7%
——6——CVE-2019-15369—20.7%
——6——CVE-2025-5302—20.7%
——6——CVE-2026-110446.5 MED20.7%
——6Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)46dCVE-2022-32509—20.7%
——6——CVE-2019-15373—20.7%
——6——CVE-2019-15375—20.7%
——6——CVE-2026-31877—20.7%
——6——CVE-2019-15383—20.7%
——6——CVE-2019-15360—20.7%
——6——CVE-2026-52705—20.7%
——6——CVE-2025-0277—20.7%
——6——CVE-2020-36206—20.7%
——6——CVE-2020-31666.7 MED20.7%
——6A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to a specific CLI command. A successful exploit could allow the attacker to read or write to arbitrary files on the underlying OS.26dCVE-2026-23923—20.7%
——6——CVE-2026-710458.8 HIG20.7%
——6Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).12dCVE-2025-65135—20.7%
——6——CVE-2025-13779—20.7%
——6——CVE-2025-57756—20.7%
——6——CVE-2026-42156—20.7%
——6——CVE-2020-36207—20.7%
——6——CVE-2025-66947—20.7%
——6——CVE-2024-54485—20.7%
——6——CVE-2019-15352—20.7%
——6——CVE-2026-478815.9 MED20.7%
——6Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for example, a CSV field that contains embedded newlines wrapped in quotes. A specially crafted input file could exploit the way the reader assembles those multi-line records to consume excessive CPU time and memory, causing the batch job to stall or run out of memory.
Spring Batch 6.0.0 - 6.0.4
Spring Batch 5.2.0 - 5.2.6
Spring Batch 4.3.0 - 4.3.135dCVE-2025-33132—20.7%
——6——CVE-2025-62906—20.7%
——6——