Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,309
- High9,908
- Medium4,857
- Low455
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-42612—14.6%
——4——CVE-2023-32441—14.6%
——4——CVE-2024-44277—14.6%
——4——CVE-2025-31222—14.6%
——4——CVE-2025-31416—14.6%
——4——CVE-2024-31413—14.6%
——4——CVE-2024-34656—14.6%
——4——CVE-2024-26774—14.6%
——4——CVE-2026-182987.8 HIG14.6%
——4GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.7dCVE-2026-138686.5 MED14.6%
——4Inappropriate implementation in Network in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)52dCVE-2023-24509—14.6%
——4——CVE-2024-49905—14.6%
——4——CVE-2026-31924—14.6%
——4——CVE-2021-47870—14.6%
——4——CVE-2025-9939—14.6%
——4——CVE-2025-53525—14.6%
——4——CVE-2022-4610—14.6%
——4——CVE-2024-49929—14.6%
——4——CVE-2026-40592—14.6%
——4——CVE-2024-358177.8 HIG14.6%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: amdgpu_ttm_gart_bind set gtt bound flag
Otherwise after the GTT bo is released, the GTT and gart space is freed
but amdgpu_ttm_backend_unbind will not clear the gart page table entry
and leave valid mapping entry pointing to the stale system page. Then
if GPU access the gart address mistakely, it will read undefined value
instead page fault, harder to debug and reproduce the real issue.23dCVE-2025-0763—14.6%
——4——CVE-2025-14719—14.6%
——4——CVE-2024-26945—14.6%
——4——CVE-2025-53377—14.6%
——4——CVE-2025-46998—14.6%
——4——CVE-2024-37535—14.6%
——4——CVE-2026-33463—14.6%
——4——CVE-2026-99086.5 MED14.6%
——4Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)37dCVE-2024-58005—14.6%
——4——CVE-2024-49897—14.6%
——4——CVE-2026-182977.8 HIG14.6%
——4GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29584.7dCVE-2024-42096—14.6%
——4——CVE-2026-672045.4 MED14.6%
——4BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints. Attackers can supply a user avatar's ID to the API controller, which loads any image type without the web controller's gallery and drawio restrictions, and when the avatar's uploaded_to field matches a page ID accessible to the attacker, the authorization check passes allowing the attacker to rename, replace, or delete the target user's avatar without requiring user-management permission.3dCVE-2025-58088—14.6%
——4——CVE-2026-44563—14.6%
——4——CVE-2025-59033—14.6%
——4——CVE-2021-28805—14.6%
——4——CVE-2025-46936—14.6%
——4——CVE-2026-49064—14.6%
——4——CVE-2025-31389—14.6%
——4——