Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,699
- High11,576
- Medium7,298
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-25132—10.5%
——3——CVE-2025-64358—10.5%
——3——CVE-2019-14066—10.5%
——3——CVE-2019-14117—10.5%
——3——CVE-2024-50214—10.5%
——3——CVE-2019-14021—10.4%
——3——CVE-2025-33101—10.4%
——3——CVE-2022-50203—10.4%
——3——CVE-2019-10548—10.4%
——3——CVE-2019-14030—10.4%
——3——CVE-2025-23430—10.4%
——3——CVE-2026-116818.8 HIG10.4%
——3Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)21dCVE-2019-14044—10.4%
——3——CVE-2019-14000—10.4%
——3——CVE-2025-23558—10.4%
——3——CVE-2025-23557—10.4%
——3——CVE-2024-42039—10.4%
——3——CVE-2019-10537—10.4%
——3——CVE-2026-452663.5 LOW10.4%
——3Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-performance Backend is installed. This issue has been patched in versions 21.1.10, 22.0.11, and 23.0.3.22dCVE-2025-23560—10.4%
——3——CVE-2024-7671—10.4%
——3——CVE-2025-32215—10.4%
——3——CVE-2022-50122—10.4%
——3——CVE-2025-23445—10.4%
——3——CVE-2019-14122—10.4%
——3——CVE-2024-39584—10.4%
——3——CVE-2024-57939—10.4%
——3——CVE-2025-37129—10.4%
——3——CVE-2026-43531—10.4%
——3——CVE-2019-10606—10.4%
——3——CVE-2019-14046—10.4%
——3——CVE-2019-14028—10.4%
——3——CVE-2019-14009—10.4%
——3——CVE-2025-27459—10.4%
——3——CVE-2025-23442—10.4%
——3——CVE-2024-1976—10.4%
——3——CVE-2025-0921—10.4%
——3——CVE-2026-1917—10.4%
——3——CVE-2022-50041—10.4%
——3——CVE-2026-145686.5 MED10.4%
——3The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8-installed placeholder media.17d