Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-647477.8 HIG15.1%
——5A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges.10dCVE-2026-20605—15.1%
——5——CVE-2025-24451—15.1%
——5——CVE-2026-42726—15.1%
——5——CVE-2026-116528.3 HIG15.1%
——5Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)36dCVE-2026-53912—15.1%
——5——CVE-2026-7595—15.1%
——5——CVE-2020-35928—15.1%
——5——CVE-2025-6865—15.1%
——5——CVE-2025-69009—15.1%
——5——CVE-2026-24455—15.1%
——5——CVE-2026-683938.8 HIG15.1%
——5In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: extend conn_hash lookup critical sections
Using RCU-protected pointers outside the critical sections without
refcount is incorrect and may result to UAF.
Extend critical section to cover both hci_conn_hash lookup and use of
the returned conn.
Add surrounding rcu_read_lock() also when return value is not used, in
preparation for RCU lockdep requirement to hci_lookup_le_connect().
This avoids concurrent deletion of the conn before we are done
dereferencing it.
Also, make sure to hold hdev->lock when accessing hdev->accept_list.11dCVE-2026-106244.3 MED15.1%
——5A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the component Employee View Page. Such manipulation of the argument employeeid leads to improper control of resource identifiers. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.36dCVE-2019-25396—15.1%
——5——CVE-2025-7440—15.1%
——5——CVE-2026-42651—15.1%
——5——CVE-2026-622215.4 MED15.1%
——5OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.37dCVE-2026-28476—15.1%
——5——CVE-2024-28681—15.1%
——5——CVE-2024-49228—15.1%
——5——CVE-2024-49232—15.1%
——5——CVE-2026-25462—15.1%
——5——CVE-2026-27362—15.1%
——5——CVE-2026-0931—15.1%
——5Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart.23dCVE-2022-28778—15.1%
——5——CVE-2023-52629—15.1%
——5——CVE-2026-479318.4 HIG15.1%
——5ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.1dCVE-2024-28670—15.1%
——5——CVE-2025-539996.5 MED15.1%
——5Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.7dCVE-2024-37554—15.1%
——5——CVE-2023-42887—15.1%
——5——CVE-2025-68049—15.1%
——5——CVE-2026-25437—15.1%
——5——CVE-2024-47587—15.1%
——5——CVE-2025-52653—15.1%
——5——CVE-2019-25398—15.1%
——5——CVE-2024-47065—15.1%
——5——CVE-2017-18278—15.1%
——5——CVE-2026-7824—15.1%
——5——CVE-2024-39866—15.1%
——5——