Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,311
- High9,926
- Medium4,860
- Low456
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-112846.5 MED14.6%
——4Side-channel information leakage in PerformanceAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)35dCVE-2026-44991—14.6%
——4——CVE-2024-26825—14.6%
——4——CVE-2025-50073—14.6%
——4——CVE-2024-10906—14.6%
——4——CVE-2026-77113—14.6%
——4Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.6dCVE-2025-66424—14.6%
——4——CVE-2023-1386—14.6%
——4——CVE-2024-37244—14.6%
——4——CVE-2024-49413—14.6%
——4——CVE-2022-37908—14.6%
——4——CVE-2026-4733—14.6%
——4——CVE-2019-25597—14.6%
——4——CVE-2022-48833—14.6%
——4——CVE-2026-20089—14.6%
——4——CVE-2026-3348—14.6%
——4——CVE-2023-45166—14.6%
——4——CVE-2026-7967—14.6%
——4——CVE-2025-1512—14.6%
——4——CVE-2026-708677.1 HIG14.6%
——4Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).3dCVE-2024-13650—14.6%
——4——CVE-2025-14540—14.6%
——4——CVE-2021-47787—14.6%
——4——CVE-2024-0091—14.6%
——4——CVE-2023-29838—14.6%
——4——CVE-2026-22393—14.6%
——4——CVE-2024-36941—14.6%
——4——CVE-2026-22430—14.6%
——4——CVE-2024-8026—14.6%
——4——CVE-2023-4688—14.6%
——4——CVE-2026-21873—14.6%
——4——CVE-2026-421744.3 MED14.6%
——4Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.34dCVE-2026-8086—14.6%
——4——CVE-2025-4202—14.6%
——4——CVE-2021-27032—14.6%
——4——CVE-2024-57948—14.6%
——4——CVE-2026-547803.7 LOW14.6%
——4CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:SignedInfo SignatureMethod against the configured SecurityAlgorithmSuite but does not validate each ds:Reference DigestMethod, allowing a sender to use a rejected digest algorithm such as SHA-1 while the message is still accepted. This issue is fixed in versions 1.8.1 and 1.9.1.49dCVE-2026-22041—14.6%
——4——CVE-2024-36957—14.6%
——4——CVE-2026-0693—14.6%
——4——