Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-38580—15.2%
——5——CVE-2026-112829.6 CRI15.2%
——5Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)36dCVE-2021-33149—15.2%
——5——CVE-2026-4090—15.2%
——5——CVE-2026-56093—15.2%
——5——CVE-2026-736508.2 HIG15.2%
——5SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as <svg:script> and, in versions 3 and 4, matches JavaScript URIs case sensitively. Applications that process untrusted SVG input with this plugin enabled and serve the result can allow scripts to execute when another user opens the SVG, exposing local storage or cookies. This issue is fixed in versions 2.8.3, 3.3.4, and 4.0.2.10dCVE-2026-157927.5 HIG15.2%
——5A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.28dCVE-2025-29867—15.2%
——5——CVE-2026-35240—15.2%
——5——CVE-2025-22031—15.2%
——5——CVE-2022-49088—15.2%
——5——CVE-2026-112358.8 HIG15.2%
——5Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)36dCVE-2021-473587.8 HIG15.2%
——5In the Linux kernel, the following vulnerability has been resolved:
staging: greybus: uart: fix tty use after free
User space can hold a tty open indefinitely and tty drivers must not
release the underlying structures until the last user is gone.
Switch to using the tty-port reference counter to manage the life time
of the greybus tty state to avoid use after free after a disconnect.24dCVE-2024-26695—15.2%
——5——CVE-2026-6001—15.2%
——5——CVE-2026-483085.9 MED15.2%
——5Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.42dCVE-2020-13598—15.2%
——5——CVE-2021-47372—15.2%
——5——CVE-2023-39328—15.2%
——5——CVE-2026-187365.0 MED15.2%
——5Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect to internal targets, including loopback addresses, link-local ranges, and cloud metadata endpoints such as 169.254.169.254, to exfiltrate internal service information via the HTML title element returned in the short URL creation response.24dCVE-2024-44262—15.2%
——5——CVE-2025-8778—15.2%
——5——CVE-2025-23312—15.2%
——5——CVE-2026-318935.5 MED15.2%
——5Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files by exploiting a symlink following vulnerability in tunnelblick-helper, reachable through the world-accessible tunnelblickd Unix socket. The socket is configured with mode 0666, allowing any local user to connect. No authorization check is performed on the connecting client. The tunnelblick-helper process constructs a path to config.ovpn inside a user-controlled .tblk directory and reads it as root without symlink validation. An attacker can create a .tblk configuration with a symlinked config.ovpn pointing to any file and request tunnelblickd to read it. This issue has been fixed in versions 9.0beta02.34dCVE-2021-34376—15.2%
——5——CVE-2023-52784—15.2%
——5——CVE-2026-112308.8 HIG15.2%
——5Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)36dCVE-2023-27979—15.2%
——5——CVE-2026-151198.3 HIG15.2%
——5Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)49dCVE-2022-50952—15.2%
——5——CVE-2025-12008—15.2%
——5——CVE-2021-0332—15.2%
——5——CVE-2026-528382.6 LOW15.2%
——5Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the `disable_booking_message` setting via a rich-text editor and later passed directly to the public `booking_message` view without escaping or sanitization. An authenticated administrator can store HTML or JavaScript in this field, enable disabled-booking mode, and trigger stored XSS in every unauthenticated visitor who opens the public booking page. Version 1.6.0 fixes the issue.44dCVE-2025-69241—15.2%
——5——CVE-2025-64182—15.2%
——5——CVE-2025-13849—15.2%
——5——CVE-2026-22821—15.2%
——5——CVE-2022-48836—15.2%
——5——CVE-2024-468318.4 HIG15.2%
——5In the Linux kernel, the following vulnerability has been resolved:
net: microchip: vcap: Fix use-after-free error in kunit test
This is a clear use-after-free error. We remove it, and rely on checking
the return code of vcap_del_rule.24dCVE-2025-53562—15.2%
——5——