Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,311
- High9,414
- Medium5,381
- Low529
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-200706.1 MED18.0%
——5A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by persuading a user to follow a link to a malicious website that is designed to submit malicious input to the affected application. A successful exploit could allow the attacker to execute arbitrary HTML or script code in the browser in the context of the VPN web server.21dCVE-2025-14365—18.0%
——5——CVE-2025-63364—18.0%
——5——CVE-2025-46451—18.0%
——5——CVE-2026-35402—18.0%
——5——CVE-2024-6631—18.0%
——5——CVE-2023-48754—18.0%
——5——CVE-2021-32496—18.0%
——5——CVE-2026-44292—18.0%
——5——CVE-2022-3149—18.0%
——5——CVE-2025-47520—18.0%
——5——CVE-2026-504497.0 HIG18.0%
——5Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.41dCVE-2024-11185—18.0%
——5——CVE-2024-49896—18.0%
——5——CVE-2026-549197.4 HIG18.0%
——5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an IP-literal host with server certificate verification enabled, SSLClient and Client in HTTPS mode skip certificate chain validation and WebSocketClient on the Mbed TLS backend skips verification altogether, allowing a man-in-the-middle attacker positioned to intercept traffic to present a crafted certificate and read or modify the traffic. This issue is fixed in version 0.47.0.50dCVE-2026-139755.3 MED18.0%
——5Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)62dCVE-2025-47622—18.0%
——5——CVE-2026-666956.5 MED18.0%
——5Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.20dCVE-2024-11803—18.0%
——5——CVE-2024-22100—18.0%
——5——CVE-2026-491627.0 HIG17.9%
——5Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.41dCVE-2025-47521—18.0%
——5——CVE-2026-140495.3 MED18.0%
——5Inappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)62dCVE-2025-47605—18.0%
——5——CVE-2025-47522—18.0%
——5——CVE-2024-33407—18.0%
——5——CVE-2026-138905.3 MED18.0%
——5Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)62dCVE-2025-12362—18.0%
——5——CVE-2025-46469—18.0%
——5——CVE-2025-47615—18.0%
——5——CVE-2024-13885—18.0%
——5——CVE-2023-42557—18.0%
——5——CVE-2025-39428—18.0%
——5——CVE-2026-427636.5 MED18.0%
——5Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data.
This issue affects SePay Gateway: from n/a through 1.1.20.43dCVE-2026-586297.0 HIG18.0%
——5Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.34dCVE-2024-5987—18.0%
——5——CVE-2026-27092—18.0%
——5——CVE-2026-822626.8 MED18.0%
——5Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server issue HTTP POST requests to internal URLs and retrieve response bodies from services on the private network.1dCVE-2025-47638—18.0%
——5——CVE-2023-48282—18.0%
——5——