Vulnerabilities exploitable today
366,910in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,352
- Medium5,308
- Low510
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-42945—16.8%
——5——CVE-2024-56614—16.8%
——5——CVE-2025-31187—16.8%
——5——CVE-2026-1095—16.8%
——5——CVE-2025-6818—16.8%
——5——CVE-2024-52353—16.8%
——5——CVE-2024-51597—16.8%
——5——CVE-2026-183625.9 MED16.8%
——5The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.31dCVE-2024-35770—16.8%
——5——CVE-2023-5902—16.8%
——5——CVE-2020-36839—16.8%
——5——CVE-2020-26181—16.8%
——5——CVE-2026-54357—16.8%
——5——CVE-2025-47854—16.8%
——5——CVE-2025-3614—16.8%
——5——CVE-2024-10848—16.8%
——5——CVE-2019-19352—16.8%
——5——CVE-2024-58132—16.8%
——5——CVE-2024-25679—16.8%
——5——CVE-2022-48837—16.8%
——5——CVE-2025-54395—16.8%
——5——CVE-2021-0108—16.8%
——5——CVE-2025-398977.5 HIG16.8%
——5In the Linux kernel, the following vulnerability has been resolved:
net: xilinx: axienet: Add error handling for RX metadata pointer retrieval
Add proper error checking for dmaengine_desc_get_metadata_ptr() which
can return an error pointer and lead to potential crashes or undefined
behaviour if the pointer retrieval fails.
Properly handle the error by unmapping DMA buffer, freeing the skb and
returning early to prevent further processing with invalid data.31dCVE-2026-99017.5 HIG16.8%
——5Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)40dCVE-2024-51588—16.8%
——5——CVE-2024-57981—16.8%
——5——CVE-2025-12677—16.8%
——5——CVE-2026-706834.3 MED16.8%
——5Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).5dCVE-2026-2845—16.8%
——5——CVE-2025-12584—16.8%
——5——CVE-2021-30987—16.8%
——5——CVE-2024-32955—16.8%
——5——CVE-2026-25229—16.8%
——5——CVE-2026-0914—16.8%
——5——CVE-2023-23911—16.8%
——5——CVE-2026-30856—16.8%
——5——CVE-2024-10881—16.8%
——5——CVE-2022-49342—16.8%
——5——CVE-2024-51581—16.8%
——5——CVE-2025-23078—16.8%
——5——