Vulnerabilities exploitable today
369,271in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,151
- High7,646
- Medium5,616
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-255617.5 HIG20.2%
——6WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board relationship, enabling attempts to upload attachments with mismatched object relationships.54dCVE-2022-49266—20.2%
——6——CVE-2024-39385—20.2%
——6——CVE-2024-42390—20.2%
——6——CVE-2015-7438—20.2%
——6——CVE-2026-112628.8 HIG20.2%
——6Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)45dCVE-2024-33015—20.2%
——6——CVE-2025-24785—20.2%
——6——CVE-2026-1541—20.2%
——6——CVE-2026-2003—20.2%
——6——CVE-2024-23169—20.2%
——6——CVE-2025-3861—20.2%
——6——CVE-2024-33020—20.2%
——6——CVE-2025-63068—20.2%
——6——CVE-2024-12268—20.2%
——6——CVE-2025-3670—20.2%
——6——CVE-2026-28715—20.2%
——6——CVE-2023-52976—20.2%
——6——CVE-2024-28572—20.2%
——6——CVE-2026-110778.8 HIG20.2%
——6Bad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)45dCVE-2024-7020—20.2%
——6——CVE-2026-8558—20.2%
——6——CVE-2026-99688.8 HIG20.2%
——6Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)47dCVE-2024-410497.8 HIG20.2%
——6In the Linux kernel, the following vulnerability has been resolved:
filelock: fix potential use-after-free in posix_lock_inode
Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode().
The request pointer had been changed earlier to point to a lock entry
that was added to the inode's list. However, before the tracepoint could
fire, another task raced in and freed that lock.
Fix this by moving the tracepoint inside the spinlock, which should
ensure that this doesn't happen.33dCVE-2025-62396—20.2%
——6——CVE-2026-4459—20.2%
——6——CVE-2019-11820—20.2%
——6——CVE-2026-8532—20.2%
——6——CVE-2026-110508.8 HIG20.2%
——6Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)45dCVE-2026-28855—20.2%
——6——CVE-2022-49675—20.2%
——6——CVE-2025-61598—20.2%
——6——CVE-2026-8518—20.2%
——6——CVE-2026-8551—20.2%
——6——CVE-2024-33026—20.2%
——6——CVE-2026-781377.5 HIG20.2%
——6The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.9dCVE-2026-110608.8 HIG20.2%
——6Use after free in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)45dCVE-2026-452864.3 MED20.2%
——6Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint for suggesting attendees. The sharing restrictions, applied to other endpoints, were not effective here. This issue has been patched in versions 5.5.17 and 6.2.3.46dCVE-2026-110558.8 HIG20.2%
——6Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)45dCVE-2026-351996.1 MED20.2%
——6SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes a 64-bit leaf count value to a helper function that accepts a 32-bit parameter. For XMSS^MT parameter sets with total tree height >= 32 (which includes standard predefined parameters), this causes silent truncation to zero, resulting in a drastically undersized scratch buffer allocation followed by a heap buffer overflow during signature computation. Exploiting this issue would require an application using SymCrypt to perform an XMSS^MT signature using an attacker-controlled parameter set. It is uncommon for applications to allow the use of attacker-controlled parameter sets for signing, since signing is a private key operation, and private keys must be trusted by definition. Additionally, XMSS(^MT) signing should only be performed in a Hardware Security Module (HSM). XMSS(^MT) signing is provided in SymCrypt only for testing purposes. This is a general rule irrespective of this CVE; XMSS(^MT) and other stateful signature schemes are only cryptographically secure when it is guaranteed that the same state cannot be reused for two different signatures, which cannot be guaranteed by software alone. For this reason, XMSS(^MT) signing is also not FIPS approved when performed outside of an HSM. Fixed in version 103.11.0.44d