Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,405
- High10,145
- Medium5,058
- Low466
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-25446—13.9%
——4——CVE-2024-38499—13.9%
——4——CVE-2024-3590—13.9%
——4——CVE-2026-502137.5 HIG13.9%
——4The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.34dCVE-2026-550137.1 HIG13.9%
——4Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.4dCVE-2026-7500—13.9%
——4——CVE-2026-141147.5 HIG13.9%
——4Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)51dCVE-2025-68040—13.9%
——4——CVE-2026-9260—13.9%
——4——CVE-2024-50617—13.9%
——4——CVE-2022-48644—13.9%
——4——CVE-2025-48747—13.9%
——4——CVE-2026-6805—13.9%
——4——CVE-2026-148049.1 CRI13.9%
——4Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.22dCVE-2026-3573—13.9%
——4——CVE-2026-712606.5 MED13.9%
——4ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_server.cpp), a text entity configured with mode: password (TEXT_MODE_PASSWORD) has its JSON "state" field correctly masked as "********", but the same serialization path unconditionally writes the raw password into the JSON "value" field via set_json_icon_state_value/set_json_value.16dCVE-2026-6599—13.9%
——4——CVE-2025-30750—13.9%
——4——CVE-2025-609317.5 HIG13.9%
——4An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.27dCVE-2025-25625—13.9%
——4——CVE-2025-43923—13.9%
——4——CVE-2022-50734—13.9%
——4——CVE-2024-13872—13.9%
——4——CVE-2026-8740—13.9%
——4——CVE-2026-4933—13.9%
——4——CVE-2022-25787—13.9%
——4——CVE-2021-1376—13.9%
——4——CVE-2026-679707.5 HIG13.9%
——4Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.19dCVE-2024-11155—13.9%
——4——CVE-2026-27579—13.9%
——4——CVE-2022-48642—13.9%
——4——CVE-2025-43357—13.9%
——4——CVE-2026-3992—13.9%
——4——CVE-2024-26607—13.9%
——4——CVE-2025-68014—13.9%
——4——CVE-2026-116338.8 HIG13.9%
——4Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)34dCVE-2024-13350—13.9%
——4——CVE-2022-23717—13.9%
——4——CVE-2026-142357.5 HIG13.9%
——4The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.29dCVE-2024-526806.1 MED13.9%
——4EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.52d