Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,699
- High11,576
- Medium7,298
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-67505—10.4%
——3——CVE-2019-2246—10.4%
——3——CVE-2025-39363—10.4%
——3——CVE-2026-7981—10.4%
——3——CVE-2025-5123—10.4%
——3——CVE-2025-53013—10.4%
——3——CVE-2025-23435—10.4%
——3——CVE-2025-23510—10.4%
——3——CVE-2019-10602—10.4%
——3——CVE-2019-14024—10.4%
——3——CVE-2019-14023—10.4%
——3——CVE-2019-10481—10.4%
——3——CVE-2026-110314.3 MED10.4%
——3Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Medium)21dCVE-2025-385998.8 HIG10.4%
——3In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: Fix possible OOB access in mt7996_tx()
Fis possible Out-Of-Boundary access in mt7996_tx routine if link_id is
set to IEEE80211_LINK_UNSPECIFIED14dCVE-2024-8612—10.4%
——3——CVE-2025-46253—10.4%
——3——CVE-2025-23533—10.4%
——3——CVE-2025-46227—10.4%
——3——CVE-2025-5398—10.4%
——3——CVE-2025-66581—10.4%
——3——CVE-2019-14105—10.4%
——3——CVE-2025-23499—10.4%
——3——CVE-2024-51480—10.4%
——3——CVE-2025-4586—10.4%
——3——CVE-2025-43753—10.4%
——3——CVE-2025-4584—10.4%
——3——CVE-2022-50199—10.4%
——3——CVE-2019-2315—10.4%
——3——CVE-2025-23537—10.4%
——3——CVE-2019-14085—10.4%
——3——CVE-2019-14018—10.4%
——3——CVE-2019-14068—10.4%
——3——CVE-2019-10558—10.4%
——3——CVE-2025-65097—10.4%
——3——CVE-2026-42227—10.4%
——3——CVE-2019-2288—10.4%
——3——CVE-2024-8896—10.4%
——3——CVE-2019-14049—10.4%
——3——CVE-2024-26984—10.4%
——3——CVE-2026-136946.5 MED10.4%
——3The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.23d