Vulnerabilities exploitable today
359,691in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,519
- High11,197
- Medium7,131
- Low645
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-21148—11.1%
——3——CVE-2026-56302—11.1%
——3——CVE-2024-42125—11.1%
——3——CVE-2025-23981—11.1%
——3——CVE-2022-21240—11.1%
——3——CVE-2024-47182—11.1%
——3——CVE-2026-179866.5 MED11.1%
——3Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)12dCVE-2021-47586—11.1%
——3——CVE-2025-39392—11.1%
——3——CVE-2023-40210—11.1%
——3——CVE-2025-23979—11.1%
——3——CVE-2023-40202—11.1%
——3——CVE-2025-58228—11.1%
——3——CVE-2021-47363—11.1%
——3——CVE-2026-647838.8 HIG11.1%
——3A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.18dCVE-2026-449245.4 MED11.1%
——3InfoScale VIOM 9.1.3 allows XSS.23dCVE-2024-3454—11.1%
——3——CVE-2020-8704—11.1%
——3——CVE-2025-66025—11.1%
——3——CVE-2025-49939—11.1%
——3——CVE-2022-48890—11.1%
——3——CVE-2024-31435—11.1%
——3——CVE-2026-489556.5 MED11.1%
——3An improper access check allows unauthorized users to access workflow stage and transition information.37dCVE-2016-20033—11.1%
——3——CVE-2025-68162—11.1%
——3——CVE-2025-23988—11.1%
——3——CVE-2026-25608—11.1%
——3STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens.
This issue was fixed in version 9.5.23dCVE-2024-266377.8 HIG11.1%
——3In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: rely on mac80211 debugfs handling for vif
mac80211 started to delete debugfs entries in certain cases, causing a
ath11k to crash when it tried to delete the entries later. Fix this by
relying on mac80211 to delete the entries when appropriate and adding
them from the vif_add_debugfs handler.11dCVE-2025-47678—11.1%
——3——CVE-2022-26374—11.1%
——3——CVE-2025-39393—11.1%
——3——CVE-2023-52223—11.1%
——3——CVE-2025-39372—11.1%
——3——CVE-2024-49403—11.1%
——3——CVE-2026-22696—11.1%
——3——CVE-2021-47398—11.1%
——3——CVE-2024-45015—11.1%
——3——CVE-2026-44113—11.1%
——3——CVE-2021-26278—11.1%
——3——CVE-2026-12588—11.1%
——3An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.30d