Vulnerabilities exploitable today
369,233in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,158
- High7,687
- Medium5,628
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-49742—19.9%
——6——CVE-2025-32548—19.9%
——6——CVE-2026-613657.8 HIG19.9%
——6Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.20dCVE-2026-6833—19.9%
——6——CVE-2024-466747.8 HIG19.9%
——6In the Linux kernel, the following vulnerability has been resolved:
usb: dwc3: st: fix probed platform device ref count on probe error path
The probe function never performs any paltform device allocation, thus
error path "undo_platform_dev_alloc" is entirely bogus. It drops the
reference count from the platform device being probed. If error path is
triggered, this will lead to unbalanced device reference counts and
premature release of device resources, thus possible use-after-free when
releasing remaining devm-managed resources.32dCVE-2025-30345—19.9%
——6——CVE-2025-32564—19.9%
——6——CVE-2024-11611—19.9%
——6——CVE-2007-1273—19.9%
——6——CVE-2025-9145—19.9%
——6——CVE-2010-2369—19.9%
——6——CVE-2024-267397.8 HIG19.9%
——6In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_mirred: don't override retval if we already lost the skb
If we're redirecting the skb, and haven't called tcf_mirred_forward(),
yet, we need to tell the core to drop the skb by setting the retcode
to SHOT. If we have called tcf_mirred_forward(), however, the skb
is out of our hands and returning SHOT will lead to UaF.
Move the retval override to the error path which actually need it.32dCVE-2026-33804—19.9%
——6——CVE-2025-44182—19.9%
——6——CVE-2026-110379.6 CRI19.9%
——6Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)45dCVE-2026-613677.8 HIG19.9%
——6Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.20dCVE-2026-613647.8 HIG19.9%
——6Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.20dCVE-2025-9138—19.9%
——6——CVE-2025-22449—19.9%
——6——CVE-2025-24866—19.9%
——6——CVE-2024-13697—19.9%
——6——CVE-2024-40993—19.9%
——6——CVE-2022-33270—19.9%
——6——CVE-2025-0512—19.9%
——6——CVE-2025-14079—19.9%
——6——CVE-2010-3161—19.9%
——6——CVE-2010-3160—19.9%
——6——CVE-2025-10632—19.9%
——6——CVE-2023-28647—19.9%
——6——CVE-2026-110308.8 HIG19.9%
——6Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Medium)45dCVE-2026-539587.6 HIG19.9%
——64gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail through PATCH /api/users/:id. The whitelist in server/api/controllers/users/update.js mass assigns these backend-managed identity attributes from user input. An attacker can place a victim's provider identifier on an attacker-controlled account, causing the default lookup in helpers such as server/api/helpers/users/get-create-one-for-github-sso.js to match the victim's first SSO login to the attacker's account before the email-linkage flow runs. The victim is logged into the attacker-controlled account, and projects, boards, or data the victim creates remain accessible through the attacker's original local credentials. This issue is fixed in version 3.3.9.17dCVE-2011-1378—19.9%
——6——CVE-2025-56697—19.9%
——6——CVE-2025-9652—19.9%
——6——CVE-2024-54176—19.9%
——6——CVE-2018-18098—19.9%
——6——CVE-2005-1039—19.9%
——6——CVE-2026-163798.8 HIG19.9%
——6Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.43dCVE-2025-0685—19.9%
——6——CVE-2026-72001—19.9%
——6——