Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,296
- High9,357
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-10995—16.4%
——5——CVE-2025-48239—16.4%
——5——CVE-2021-33103—16.4%
——5——CVE-2025-32180—16.4%
——5——CVE-2024-22705—16.4%
——5——CVE-2025-8675—16.4%
——5——CVE-2022-45919—16.4%
——5——CVE-2025-48235—16.4%
——5——CVE-2026-200285.0 MED16.4%
——5A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker.
This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.23dCVE-2022-49615—16.4%
——5——CVE-2025-55585—16.4%
——5——CVE-2026-116648.8 HIG16.4%
——5Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)38dCVE-2026-29135—16.4%
——5——CVE-2020-22429—16.4%
——5——CVE-2025-13753—16.4%
——5——CVE-2025-46633—16.4%
——5——CVE-2021-33124—16.4%
——5——CVE-2026-24927.8 HIG16.4%
——5TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TensorFlow. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the handling of plugins. The application loads plugins from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-25480.46dCVE-2022-42313—16.4%
——5——CVE-2026-578865.9 MED16.4%
——5Cross-repository issue/comment attachment re-linking can expose private attachment content3dCVE-2026-5776—16.4%
——5——CVE-2018-9501—16.4%
——5——CVE-2019-5283—16.4%
——5——CVE-2025-53743—16.4%
——5——CVE-2026-4185—16.4%
——5——CVE-2024-31963—16.4%
——5——CVE-2024-44100—16.4%
——5——CVE-2024-28851—16.4%
——5——CVE-2024-4689—16.4%
——5——CVE-2025-48232—16.4%
——5——CVE-2021-47310—16.4%
——5——CVE-2026-41300—16.4%
——5——CVE-2022-42316—16.4%
——5——CVE-2025-1412—16.4%
——5——CVE-2017-14904—16.4%
——5——CVE-2024-50134—16.4%
——5——CVE-2026-4428—16.4%
——5——CVE-2026-543646.5 MED16.4%
——5CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to the SelectProvider.aspx endpoint. Attackers can exploit the lack of input sanitization in the custom session serialization format to inject a resellerid session variable, bypassing the IsValidRSession authentication check and gaining unauthorized access to management pages.30dCVE-2026-444086.3 MED16.4%
——5There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can modify configuration through the interface.37dCVE-2025-48250—16.4%
——5——