Vulnerabilities exploitable today
363,765in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,906
- High12,010
- Medium7,334
- Low675
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-7277—12.8%
——4——CVE-2025-7237—12.8%
——4——CVE-2025-23744—12.8%
——4——CVE-2025-7265—12.8%
——4——CVE-2025-50011—12.8%
——4——CVE-2025-21812—12.8%
——4——CVE-2025-7269—12.8%
——4——CVE-2025-7279—12.8%
——4——CVE-2026-328607.8 HIG12.8%
——4There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvlib file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.28dCVE-2026-10733—12.8%
——4——CVE-2024-35771—12.8%
——4——CVE-2026-41002—12.8%
——4——CVE-2025-7239—12.8%
——4——CVE-2019-10598—12.8%
——4——CVE-2025-7262—12.8%
——4——CVE-2025-7236—12.8%
——4——CVE-2026-411876.5 MED12.8%
——4Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.14dCVE-2026-8688—12.8%
——4——CVE-2025-59289—12.8%
——4——CVE-2026-141518.3 HIG12.8%
——4Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)51dCVE-2025-7241—12.8%
——4——CVE-2026-356793.5 LOW12.8%
——4Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.28dCVE-2026-25147—12.8%
——4——CVE-2025-7231—12.8%
——4——CVE-2020-1861—12.8%
——4——CVE-2025-7261—12.8%
——4——CVE-2021-1392—12.8%
——4——CVE-2019-2267—12.8%
——4——CVE-2024-35772—12.8%
——4——CVE-2025-7274—12.8%
——4——CVE-2021-25509—12.8%
——4——CVE-2025-53541—12.8%
——4——CVE-2025-7272—12.8%
——4——CVE-2025-7256—12.8%
——4——CVE-2026-26883—12.8%
——4——CVE-2025-7249—12.8%
——4——CVE-2019-10603—12.8%
——4——CVE-2025-7271—12.8%
——4——CVE-2025-43581—12.8%
——4——CVE-2026-28418—12.8%
——4——