Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,699
- High11,582
- Medium7,301
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-2329—10.4%
——3——CVE-2022-3859—10.4%
——3——CVE-2026-141274.3 MED10.4%
——3Inappropriate implementation in Printing in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)42dCVE-2026-116998.8 HIG10.4%
——3Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)21dCVE-2026-86768.8 HIG10.4%
——3An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.21dCVE-2025-6462—10.4%
——3——CVE-2026-20060—10.4%
——3——CVE-2025-54191—10.4%
——3——CVE-2023-20928—10.4%
——3——CVE-2025-54190—10.4%
——3——CVE-2025-87323.3 LOW10.4%
——3A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."43dCVE-2025-54192—10.4%
——3——CVE-2026-23368.8 HIG10.4%
——3A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03.22hCVE-2018-252565.5 MED10.4%
——3IP TOOLS 2.50 contains a local buffer overflow vulnerability in the SNMP Scanner component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data into the 'From Addr' and 'To Addr' fields and trigger the crash by clicking the Start button, causing denial of service and SEH overwrite.20dCVE-2024-45102—10.4%
——3——CVE-2015-10130—10.4%
——3——CVE-2025-43197—10.4%
——3——CVE-2026-100337.3 HIG10.4%
——3The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON management capabilities and the upload_files capability to any non-administrator WordPress role or user, escalating their privileges within the site. The administrator role is protected by an early-return guard in update_role_caps(), so only non-administrator roles and individual users can be targeted; however, the same unauthenticated exposure also allows attackers to enumerate all WordPress users with their IDs and display names, disclose role and user capability state along with nonce values, and tamper with event-to-user term assignments.20dCVE-2025-23800—10.4%
——3——CVE-2022-50923—10.4%
——3——CVE-2025-398498.8 HIG10.4%
——3In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result()
If the ssid->datalen is more than IEEE80211_MAX_SSID_LEN (32) it would
lead to memory corruption so add some bounds checking.14dCVE-2026-343465.5 MED10.4%
——3Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.22dCVE-2025-54188—10.4%
——3——CVE-2026-21272—10.4%
——3——CVE-2026-2027—10.4%
——3——CVE-2025-12728—10.4%
——3——CVE-2024-39425—10.4%
——3——CVE-2025-40800—10.4%
——3——CVE-2025-5540—10.4%
——3——CVE-2025-54202—10.4%
——3——CVE-2025-23793—10.4%
——3——CVE-2023-54056—10.4%
——3——CVE-2024-49750—10.4%
——3——CVE-2024-1910—10.4%
——3——CVE-2025-13013—10.4%
——3——CVE-2020-11237—10.4%
——3——CVE-2023-25545—10.4%
——3——CVE-2025-54204—10.4%
——3——CVE-2026-164238.8 HIG10.4%
——3Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)20dCVE-2025-54189—10.4%
——3——