Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,699
- High11,576
- Medium7,298
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-67859—10.4%
——3——CVE-2018-11838—10.4%
——3——CVE-2019-2321—10.4%
——3——CVE-2019-14029—10.4%
——3——CVE-2023-40394—10.4%
——3——CVE-2019-10583—10.4%
——3——CVE-2019-14060—10.4%
——3——CVE-2023-38538—10.4%
——3——CVE-2026-116878.8 HIG10.4%
——3Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)21dCVE-2025-46228—10.4%
——3——CVE-2026-153596.5 MED10.4%
——3The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the site's cloud template library to attacker-controlled content.6dCVE-2026-141304.3 MED10.4%
——3Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)42dCVE-2019-10604—10.4%
——3——CVE-2024-34010—10.4%
——3——CVE-2026-116979.6 CRI10.4%
——3Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)21dCVE-2026-451593.5 LOW10.4%
——3Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with access to an end-to-end encrypted files drop link was able to also drop files into other end-to-end encrypted folders of the share owner. Reading and modifying of other files was not possible. This issue has been patched in versions 1.15.4, 1.16.3, 1.17.1, 1.18.1, and 2.0.0-rc.7.22dCVE-2022-50220—10.4%
——3——CVE-2025-46236—10.4%
——3——CVE-2019-2339—10.4%
——3——CVE-2026-461668.8 HIG10.4%
——3In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: use safe list iteration in radar detect work
The call to ieee80211_dfs_cac_cancel can cause the iterated chanctx to
be freed and removed from the list. Guard against this to avoid a
slab-use-after-free error.29dCVE-2025-23501—10.4%
——3——CVE-2026-0955—10.4%
——3——CVE-2026-29934—10.4%
——3——CVE-2025-23508—10.4%
——3——CVE-2019-10582—10.4%
——3——CVE-2020-3687—10.4%
——3——CVE-2025-23436—10.4%
——3——CVE-2025-23511—10.4%
——3——CVE-2023-26278—10.4%
——3——CVE-2025-23497—10.4%
——3——CVE-2025-46237—10.4%
——3——CVE-2025-23513—10.4%
——3——CVE-2026-141404.3 MED10.4%
——3Insufficient validation of untrusted input in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)38dCVE-2019-14032—10.4%
——3——CVE-2026-116988.8 HIG10.4%
——3Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)21dCVE-2019-14034—10.4%
——3——CVE-2022-25328—10.4%
——3——CVE-2019-10585—10.4%
——3——CVE-2025-46238—10.4%
——3——CVE-2026-41299—10.4%
——3——