Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-38456—15.2%
——5——CVE-2024-4187—15.2%
——5——CVE-2022-46783—15.2%
——5——CVE-2024-28049—15.2%
——5——CVE-2023-27970—15.2%
——5——CVE-2026-116738.8 HIG15.2%
——5Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)36dCVE-2023-27977—15.2%
——5——CVE-2026-41379—15.2%
——5——CVE-2024-58108—15.2%
——5——CVE-2022-31599—15.2%
——5——CVE-2008-2368—15.2%
——5——CVE-2026-325897.4 HIG15.2%
——5A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.11dCVE-2023-43555—15.2%
——5——CVE-2008-2367—15.2%
——5——CVE-2023-50706—15.2%
——5——CVE-2025-609587.3 HIG15.2%
——5Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.53dCVE-2026-40148—15.2%
——5——CVE-2022-50763—15.2%
——5——CVE-2026-185107.2 HIG15.2%
——5The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation may delay exploitation for first-time commenters, but does not prevent it, as the payload uses only WordPress-permitted tags and attributes with percent-encoded characters that pass wp_kses URL validation unmodified.15dCVE-2018-9381—15.2%
——5——CVE-2026-48794.3 MED15.2%
——5GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint.8dCVE-2026-184334.3 MED15.2%
——5GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due to incorrect authorization checks in a GraphQL query.8dCVE-2026-179919.6 CRI15.2%
——5Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)24dCVE-2025-5766—15.2%
——5——CVE-2025-53657—15.2%
——5——CVE-2026-33051—15.2%
——5——CVE-2023-39929—15.2%
——5——CVE-2026-98759.6 CRI15.2%
——5Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)38dCVE-2026-5496—15.2%
——5——CVE-2025-55663—15.2%
——5——CVE-2023-23543—15.2%
——5——CVE-2024-58106—15.2%
——5——CVE-2024-13845—15.2%
——5——CVE-2025-58978—15.2%
——5——CVE-2026-290237.3 HIG15.2%
——5Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network attackers to authenticate using the publicly known static key. An attacker able to reach the router port can proxy requests through the Shannon instance using the victim’s configured upstream provider API credentials, resulting in unauthorized API usage and potential disclosure of proxied request and response data. This vulnerability's general exploitability has been mitigated with the introduction of commit 023cc95.44dCVE-2022-23720—15.2%
——5——CVE-2025-54733—15.2%
——5——CVE-2025-55644—15.2%
——5——CVE-2025-42886—15.2%
——5——CVE-2026-52695—15.2%
——5——