Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,688
- High11,548
- Medium7,259
- Low674
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-3640—10.6%
——3——CVE-2024-35425—10.6%
——3——CVE-2026-164138.3 HIG10.6%
——3Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)20dCVE-2024-23457—10.6%
——3——CVE-2019-18243—10.6%
——3——CVE-2025-58134—10.6%
——3——CVE-2022-45858—10.6%
——3——CVE-2019-18255—10.6%
——3——CVE-2025-64683—10.6%
——3——CVE-2025-62000—10.6%
——3——CVE-2023-20519—10.6%
——3——CVE-2024-3472—10.6%
——3——CVE-2023-46201—10.6%
——3——CVE-2025-53520—10.5%
——3——CVE-2025-57706—10.6%
——3——CVE-2025-68042—10.6%
——3——CVE-2025-377897.8 HIG10.6%
——3In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: fix nested key length validation in the set() action
It's not safe to access nla_len(ovs_key) if the data is smaller than
the netlink header. Check that the attribute is OK first.14dCVE-2023-32424—10.6%
——3——CVE-2022-50006—10.6%
——3——CVE-2025-62340—10.6%
——3——CVE-2026-4075—10.6%
——3——CVE-2024-32699—10.6%
——3——CVE-2021-0459—10.6%
——3——CVE-2025-21835—10.6%
——3——CVE-2024-44157—10.6%
——3——CVE-2026-2319—10.6%
——3——CVE-2025-62920—10.6%
——3——CVE-2026-29175—10.6%
——3——CVE-2026-667117.1 HIG10.6%
——3Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.19hCVE-2025-47610—10.6%
——3——CVE-2026-25647—10.6%
——3——CVE-2024-20807—10.6%
——3——CVE-2023-31174—10.6%
——3——CVE-2025-20892—10.6%
——3——CVE-2025-3027—10.6%
——3——CVE-2026-5022—10.6%
——3——CVE-2026-25702—10.5%
——3——CVE-2025-24862—10.6%
——3——CVE-2025-58850—10.6%
——3——CVE-2026-1437—10.6%
——3——