Vulnerabilities exploitable today
366,910in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,352
- Medium5,308
- Low510
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-54357—16.8%
——5——CVE-2025-47854—16.8%
——5——CVE-2020-26181—16.8%
——5——CVE-2025-12677—16.8%
——5——CVE-2021-30987—16.8%
——5——CVE-2025-6818—16.8%
——5——CVE-2024-52353—16.8%
——5——CVE-2024-51597—16.8%
——5——CVE-2025-61959—16.8%
——5——CVE-2025-611647.5 HIG16.8%
——5Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.2dCVE-2024-51591—16.8%
——5——CVE-2026-99097.5 HIG16.8%
——5Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)40dCVE-2026-65414.3 MED16.7%
——5Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-0065347dCVE-2019-5281—16.7%
——5——CVE-2025-26700—16.7%
——5——CVE-2022-48946—16.7%
——5——CVE-2024-12112—16.7%
——5——CVE-2022-47896—16.7%
——5——CVE-2026-27934—16.7%
——5——CVE-2024-34791—16.7%
——5——CVE-2026-655374.3 MED16.7%
——5Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.38dCVE-2023-3610—16.7%
——5——CVE-2022-21226—16.7%
——5——CVE-2021-33082—16.7%
——5——CVE-2024-11450—16.7%
——5——CVE-2022-1823—16.7%
——5——CVE-2025-713956.5 MED16.7%
——5SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to restrict resulting string length when using regex patterns. An authenticated attacker can craft a malicious query to exhaust server memory through unbounded string allocations, causing denial of service.11dCVE-2026-28510—16.7%
——5——CVE-2021-33220—16.7%
——5——CVE-2025-13001—16.7%
——5——CVE-2025-58714—16.7%
——5——CVE-2026-30994—16.7%
——5——CVE-2024-35704—16.7%
——5——CVE-2026-619734.3 MED16.7%
——5Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.38dCVE-2026-709607.6 HIG16.7%
——5Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).6dCVE-2024-47581—16.7%
——5——CVE-2024-45471—16.7%
——5——CVE-2025-52757—16.7%
——5——CVE-2026-33354—16.7%
——5——CVE-2019-18244—16.7%
——5——