Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,296
- High9,357
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-27624—16.6%
——5——CVE-2026-733568.2 HIG16.6%
——5Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.10dCVE-2026-140826.5 MED16.6%
——5Race in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)59dCVE-2023-49574—16.6%
——5——CVE-2023-41139—16.6%
——5——CVE-2019-5217—16.6%
——5——CVE-2024-44683—16.6%
——5——CVE-2020-11488—16.6%
——5——CVE-2023-49575—16.6%
——5——CVE-2024-28984—16.6%
——5——CVE-2025-53461—16.6%
——5——CVE-2023-49573—16.6%
——5——CVE-2024-8471—16.6%
——5——CVE-2025-36160—16.6%
——5——CVE-2024-51472—16.6%
——5——CVE-2018-1877—16.6%
——5——CVE-2026-140156.5 MED16.6%
——5Race in WebRTC in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)59dCVE-2026-20611—16.6%
——5——CVE-2023-40671—16.6%
——5——CVE-2024-33991—16.6%
——5——CVE-2025-24339—16.6%
——5——CVE-2026-00516.5 MED16.6%
——5In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.39dCVE-2020-7290—16.6%
——5——CVE-2022-49712—16.6%
——5——CVE-2022-49228—16.6%
——5——CVE-2023-25480—16.6%
——5——CVE-2026-00526.5 MED16.6%
——5In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.39dCVE-2024-33994—16.6%
——5——CVE-2024-38559—16.6%
——5——CVE-2024-34766—16.6%
——5——CVE-2022-49403—16.6%
——5——CVE-2022-49628—16.6%
——5——CVE-2026-17598—16.6%
——5Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the system to overwrite the configuration of an unrelated, existing task instead of creating a new one.22dCVE-2023-44297—16.6%
——5——CVE-2026-580415.3 MED16.6%
——5A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanism introduced for StatementSync in recent releases
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.25dCVE-2026-107386.4 MED16.6%
——5The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...}}' Syntax) in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attribute-breakout payload (e.g., a double-quote followed by an event handler) contains no angle brackets and therefore bypasses WordPress core's wp_kses_post() filtering, which only strips disallowed HTML tags rather than sanitizing attribute contexts.38dCVE-2025-56761—16.6%
——5——CVE-2025-13855—16.6%
——5——CVE-2022-49659—16.6%
——5——CVE-2022-49704—16.6%
——5——