Vulnerabilities exploitable today
367,851in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,393
- High9,631
- Medium5,587
- Low548
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-21092—18.5%
——6——CVE-2026-6497—18.5%
——6——CVE-2018-87247.8 HIG18.5%
——6K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is: K7TSMngr.exe.55dCVE-2010-3014—18.5%
——6——CVE-2026-30077—18.5%
——6——CVE-2017-16555—18.5%
——6——CVE-2022-20022—18.5%
——6——CVE-2024-1415—18.5%
——6——CVE-2022-4386—18.5%
——6——CVE-2025-57424—18.5%
——6——CVE-2026-36837—18.5%
——6——CVE-2025-5884—18.5%
——6——CVE-2024-12872—18.5%
——6——CVE-2017-16557—18.5%
——6——CVE-2026-24800—18.5%
——6——CVE-2025-30369—18.5%
——6——CVE-2026-448137.8 HIG18.5%
——6Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.41dCVE-2026-448087.8 HIG18.5%
——6Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.41dCVE-2025-70963—18.5%
——6——CVE-2022-20021—18.5%
——6——CVE-2024-41825—18.5%
——6——CVE-2019-14603—18.5%
——6——CVE-2014-7449—18.4%
——6——CVE-2026-324639.9 CRI18.4%
——6Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.13dCVE-2014-6960—18.4%
——6——CVE-2014-6905—18.4%
——6——CVE-2014-6933—18.4%
——6——CVE-2024-9269—18.4%
——6——CVE-2022-49331—18.4%
——6——CVE-2025-53291—18.4%
——6——CVE-2014-7391—18.4%
——6——CVE-2014-6982—18.4%
——6——CVE-2014-6959—18.4%
——6——CVE-2024-34477—18.4%
——6——CVE-2026-663948.7 HIG18.4%
——6SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements which the HTML parser treats as raw text but browsers interpret as executable SVG content when served as image/svg+xml, enabling script execution in the application origin.35dCVE-2025-69276—18.4%
——6——CVE-2022-26862—18.4%
——6——CVE-2024-27033—18.4%
——6——CVE-2026-441049.8 CRI18.4%
——6The firmware update process for the basemodule of the charging controller only validates the
CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.34dCVE-2025-60097—18.4%
——6——