Vulnerabilities exploitable today
369,139in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,634
Distribution · last window
- Critical2,182
- High7,845
- Medium5,725
- Low553
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-24655—19.6%
——6——CVE-2024-20510—19.6%
——6——CVE-2025-39505—19.6%
——6——CVE-2026-110959.6 CRI19.6%
——6Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)44dCVE-2025-66314—19.6%
——6——CVE-2025-32527—19.6%
——6——CVE-2025-24586—19.6%
——6——CVE-2025-12217—19.6%
——6——CVE-2022-49474—19.6%
——6——CVE-2024-11885—19.6%
——6——CVE-2025-32529—19.6%
——6——CVE-2026-2756—19.6%
——6——CVE-2024-35719—19.6%
——6——CVE-2024-49355—19.6%
——6——CVE-2025-54559—19.6%
——6——CVE-2024-56223—19.6%
——6——CVE-2026-33545—19.6%
——6——CVE-2022-49653—19.6%
——6——CVE-2022-49505—19.6%
——6——CVE-2025-41344—19.6%
——6——CVE-2025-54338—19.6%
——6——CVE-2026-24587—19.6%
——6——CVE-2024-56209—19.6%
——6——CVE-2026-2947—19.6%
——6——CVE-2025-13025—19.6%
——6——CVE-2025-10705—19.6%
——6——CVE-2026-3977—19.6%
——6——CVE-2024-53408—19.6%
——6——CVE-2026-759786.3 MED19.6%
——6A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.15dCVE-2022-4745—19.6%
——6——CVE-2025-27313—19.6%
——6——CVE-2025-46437—19.6%
——6——CVE-2026-115155.3 MED19.6%
——6A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such manipulation of the argument new_password with the input password123 leads to use of hard-coded password. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.44dCVE-2025-41339—19.6%
——6——CVE-2024-12518—19.6%
——6——CVE-2025-22263—19.6%
——6——CVE-2024-270357.3 HIG19.6%
——6In the Linux kernel, the following vulnerability has been resolved:
f2fs: compress: fix to guarantee persisting compressed blocks by CP
If data block in compressed cluster is not persisted with metadata
during checkpoint, after SPOR, the data may be corrupted, let's
guarantee to write compressed page by checkpoint.32dCVE-2024-11883—19.6%
——6——CVE-2025-52357—19.6%
——6——CVE-2024-9619—19.6%
——6——