Vulnerabilities exploitable today
369,233in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,158
- High7,687
- Medium5,628
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-44975—19.9%
——6——CVE-2026-47182—19.9%
——6——CVE-2019-14477—19.9%
——6——CVE-2024-52998—19.9%
——6——CVE-2026-72001—19.9%
——6——CVE-2025-0685—19.9%
——6——CVE-2020-10636—19.9%
——6——CVE-2024-36406—19.9%
——6——CVE-2026-20205—19.9%
——6——CVE-2026-0890—19.9%
——6——CVE-2024-20504—19.9%
——6——CVE-2025-11188—19.9%
——6——CVE-2025-24234—19.9%
——6——CVE-2025-27500—19.9%
——6——CVE-2026-99637.5 HIG19.9%
——6Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)46dCVE-2023-32538—19.9%
——6——CVE-2026-646238.6 HIG19.9%
——6Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.44dCVE-2026-703787.5 HIG19.9%
——6imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seam_carving::shrink_width — a function that panics when given a width below 2, crashing the process.8dCVE-2026-139316.5 MED19.9%
——6Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)66dCVE-2024-39242—19.9%
——6——CVE-2025-49419—19.9%
——6——CVE-2005-1039—19.9%
——6——CVE-2024-54176—19.9%
——6——CVE-2018-18098—19.9%
——6——CVE-2022-40884—19.9%
——6——CVE-2024-2537—19.9%
——6——CVE-2026-44976—19.9%
——6——CVE-2023-45168—19.9%
——6——CVE-2018-11862—19.9%
——6——CVE-2008-4407—19.9%
——6——CVE-2014-0083—19.9%
——6——CVE-2026-28114—19.9%
——6——CVE-2026-30587—19.9%
——6——CVE-2024-8472—19.9%
——6——CVE-2010-2784—19.9%
——6——CVE-2024-44154—19.9%
——6——CVE-2022-33746—19.9%
——6——CVE-2023-32201—19.9%
——6——CVE-2026-41708—19.9%
——6——CVE-2022-50728—19.8%
——6——