Vulnerabilities exploitable today
363,254in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,901
- High12,396
- Medium7,640
- Low722
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-178386.5 MED12.6%
——4Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)17dCVE-2024-49791—12.6%
——4——CVE-2026-32390—12.6%
——4——CVE-2025-10198—12.6%
——4——CVE-2025-12520—12.6%
——4——CVE-2022-50735—12.6%
——4——CVE-2023-0629—12.6%
——4——CVE-2022-20493—12.6%
——4——CVE-2025-50013—12.6%
——4——CVE-2025-50019—12.6%
——4——CVE-2025-50023—12.6%
——4——CVE-2025-48313—12.6%
——4——CVE-2026-32385—12.6%
——4——CVE-2026-178196.5 MED12.6%
——4Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)17dCVE-2025-50022—12.6%
——4——CVE-2026-396885.3 MED12.6%
——4Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9.27dCVE-2022-22148—12.6%
——4——CVE-2022-50859—12.6%
——4——CVE-2025-50025—12.6%
——4——CVE-2025-46229—12.6%
——4——CVE-2025-50016—12.6%
——4——CVE-2026-178286.5 MED12.6%
——4Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)17dCVE-2025-22262—12.6%
——4——CVE-2025-50027—12.6%
——4——CVE-2026-178356.5 MED12.6%
——4Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)17dCVE-2025-50021—12.6%
——4——CVE-2026-7134—12.6%
——4——CVE-2023-38746—12.6%
——4——CVE-2026-7133—12.6%
——4——CVE-2026-3875—12.6%
——4——CVE-2026-5396—12.6%
——4——CVE-2025-69749—12.6%
——4——CVE-2026-457393.1 LOW12.6%
——4Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as `Authorization: Bearer <token>`, the value could become visible in browser history, copied links, and server/proxy/CDN access logs after a page reload or shared request. Version 0.315.4 patches the issue.29dCVE-2020-35514—12.6%
——4——CVE-2026-6220—12.6%
——4——CVE-2025-43735—12.6%
——4——CVE-2024-57910—12.6%
——4——CVE-2025-10151—12.6%
——4——CVE-2026-33865—12.6%
——4——CVE-2024-57908—12.6%
——4——