Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,687
- High11,543
- Medium7,255
- Low674
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-58621—10.6%
——3——CVE-2025-58808—10.6%
——3——CVE-2026-627747.0 HIG10.6%
——3Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.2dCVE-2026-657817.0 HIG10.6%
——3Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.2dCVE-2026-657807.0 HIG10.6%
——3Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.1dCVE-2026-657827.0 HIG10.6%
——3Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.2dCVE-2026-627537.0 HIG10.6%
——3Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.1dCVE-2025-58605—10.6%
——3——CVE-2025-23821—10.6%
——3——CVE-2025-23820—10.6%
——3——CVE-2025-24155—10.6%
——3——CVE-2025-23871—10.6%
——3——CVE-2026-664084.6 MED10.6%
——3The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.
Physical access to an affected product may allow to obtain the password of the root account.3dCVE-2024-57178—10.6%
——3——CVE-2025-48316—10.6%
——3——CVE-2021-22571—10.6%
——3——CVE-2023-35699—10.6%
——3——CVE-2025-10729—10.6%
——3The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free.15dCVE-2025-58823—10.6%
——3——CVE-2021-32577—10.6%
——3——CVE-2026-354666.1 MED10.6%
——3XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services20dCVE-2025-23818—10.6%
——3——CVE-2025-48312—10.6%
——3——CVE-2026-22999—10.6%
——3——CVE-2023-49618—10.6%
——3——CVE-2026-567724.3 MED10.6%
——3NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/interactions endpoint without ownership verification. Attackers can enumerate user_id values to access another user's follows, replies, and social activity without authorization.30dCVE-2025-23822—10.6%
——3——CVE-2025-58793—10.6%
——3——CVE-2025-23823—10.6%
——3——CVE-2021-24038—10.6%
——3——CVE-2022-30741—10.6%
——3——CVE-2024-2970—10.6%
——3——CVE-2018-11976—10.6%
——3——CVE-2018-11971—10.6%
——3——CVE-2022-4894—10.6%
——3——CVE-2023-34044—10.6%
——3——CVE-2025-58602—10.6%
——3——CVE-2026-3001—10.6%
——3——CVE-2026-32899—10.6%
——3——CVE-2025-58610—10.6%
——3——