Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,337
- High10,008
- Medium4,921
- Low461
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-49005—14.4%
——4——CVE-2022-48994—14.4%
——4——CVE-2025-58622—14.4%
——4——CVE-2022-48973—14.4%
——4——CVE-2024-41095—14.4%
——4——CVE-2026-177814.3 MED14.4%
——4Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)24dCVE-2025-58617—14.4%
——4——CVE-2025-53341—14.4%
——4——CVE-2026-22741—14.4%
——4——CVE-2026-1894—14.4%
——4——CVE-2025-8996—14.4%
——4——CVE-2026-33462—14.4%
——4——CVE-2025-58601—14.4%
——4——CVE-2026-503257.0 HIG14.4%
——4Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.36dCVE-2022-49010—14.4%
——4——CVE-2020-12376—14.4%
——4——CVE-2024-46832—14.4%
——4——CVE-2024-45474—14.4%
——4——CVE-2024-49937—14.4%
——4——CVE-2024-46810—14.4%
——4——CVE-2024-53231—14.4%
——4——CVE-2024-49946—14.4%
——4——CVE-2024-49891—14.4%
——4——CVE-2025-58663—14.4%
——4——CVE-2025-12449—14.4%
——4——CVE-2026-78373.7 LOW14.4%
——4A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited data modification under specific race conditions.35dCVE-2026-73278.1 HIG14.4%
——4An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.20dCVE-2026-502977.0 HIG14.4%
——4Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.36dCVE-2026-35447—14.4%
——4NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer is authorized to access the profile. This allows any user with the profile.post permission to write wall posts to private or blocking profiles. Additionally, the reply branch does not verify that the target wall post belongs to the current profile, enabling attackers to inject replies into arbitrary wall posts owned by other profiles via a restricted profile URL. This is patched in version 2.2.5.36dCVE-2024-50121—14.4%
——4——CVE-2026-3553—14.4%
——4——CVE-2024-47731—14.4%
——4——CVE-2022-49011—14.4%
——4——CVE-2025-24836—14.4%
——4——CVE-2025-63043—14.4%
——4——CVE-2025-58817—14.4%
——4——CVE-2025-61583—14.4%
——4——CVE-2025-58664—14.4%
——4——CVE-2025-65417—14.3%
——4——CVE-2022-48840—14.3%
——4——