Vulnerabilities exploitable today
363,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,856
- High11,759
- Medium7,145
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-41382—13.1%
——4——CVE-2026-42545—13.1%
——4——CVE-2026-99328.3 HIG13.1%
——4Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)32dCVE-2024-25112—13.1%
——4——CVE-2019-5267—13.1%
——4——CVE-2024-43868—13.1%
——4——CVE-2020-274184.4 MED13.1%
——4A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.44dCVE-2024-47743—13.1%
——4——CVE-2025-1384—13.1%
——4——CVE-2025-46391—13.1%
——4——CVE-2026-7956—13.1%
——4——CVE-2026-41078—13.1%
——4——CVE-2026-41381—13.1%
——4——CVE-2022-50179—13.1%
——4——CVE-2026-10820—13.1%
——4——CVE-2025-13071—13.1%
——4——CVE-2023-5616—13.1%
——4——CVE-2025-54341—13.1%
——4——CVE-2024-10013—13.1%
——4——CVE-2021-27192—13.1%
——4——CVE-2026-99168.3 HIG13.1%
——4Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)32dCVE-2022-48757—13.1%
——4——CVE-2024-48121—13.1%
——4——CVE-2023-42555—13.1%
——4——CVE-2024-219445.3 MED13.1%
——4Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity.30dCVE-2022-35860—13.1%
——4——CVE-2025-11014—13.1%
——4——CVE-2021-28498—13.1%
——4——CVE-2023-32283—13.1%
——4——CVE-2022-43850—13.1%
——4——CVE-2023-22390—13.1%
——4——CVE-2025-54744—13.1%
——4——CVE-2025-46389—13.1%
——4——CVE-2026-99498.3 HIG13.1%
——4Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)32dCVE-2026-20676—13.1%
——4——CVE-2025-40078—13.1%
——4In the Linux kernel, the following vulnerability has been resolved:
bpf: Explicitly check accesses to bpf_sock_addr
Syzkaller found a kernel warning on the following sock_addr program:
0: r0 = 0
1: r2 = *(u32 *)(r1 +60)
2: exit
which triggers:
verifier bug: error during ctx access conversion (0)
This is happening because offset 60 in bpf_sock_addr corresponds to an
implicit padding of 4 bytes, right after msg_src_ip4. Access to this
padding isn't rejected in sock_addr_is_valid_access and it thus later
fails to convert the access.
This patch fixes it by explicitly checking the various fields of
bpf_sock_addr in sock_addr_is_valid_access.
I checked the other ctx structures and is_valid_access functions and
didn't find any other similar cases. Other cases of (properly handled)
padding are covered in new tests in a subsequent patch.39dCVE-2026-99368.3 HIG13.1%
——4Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)32dCVE-2020-11129—13.1%
——4——CVE-2026-115467.1 HIG13.1%
——4IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.50dCVE-2023-20035—13.1%
——4——