Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,699
- High11,582
- Medium7,301
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-13013—10.4%
——3——CVE-2026-34673—10.4%
——3——CVE-2026-151139.6 CRI10.4%
——3Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)34dCVE-2024-0847—10.4%
——3——CVE-2025-43291—10.4%
——3——CVE-2025-54203—10.4%
——3——CVE-2026-151238.8 HIG10.4%
——3Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)34dCVE-2023-25545—10.4%
——3——CVE-2020-11246—10.4%
——3——CVE-2022-36414—10.4%
——3——CVE-2024-1907—10.4%
——3——CVE-2026-112939.6 CRI10.4%
——3Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)21dCVE-2025-21750—10.4%
——3——CVE-2024-56685—10.4%
——3——CVE-2026-141414.3 MED10.4%
——3Incorrect security UI in Document Picture-in-Picture in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)38dCVE-2024-577939.3 CRI10.4%
——3In the Linux kernel, the following vulnerability has been resolved:
virt: tdx-guest: Just leak decrypted memory on unrecoverable errors
In CoCo VMs it is possible for the untrusted host to cause
set_memory_decrypted() to fail such that an error is returned
and the resulting memory is shared. Callers need to take care
to handle these errors to avoid returning decrypted (shared)
memory to the page allocator, which could lead to functional
or security issues.
Leak the decrypted memory when set_memory_decrypted() fails,
and don't need to print an error since set_memory_decrypted()
will call WARN_ONCE().9dCVE-2025-54193—10.4%
——3——CVE-2025-66017—10.4%
——3——CVE-2025-53290—10.4%
——3——CVE-2026-20178—10.4%
——3——CVE-2025-54202—10.4%
——3——CVE-2024-49750—10.4%
——3——CVE-2023-54056—10.4%
——3——CVE-2025-54188—10.4%
——3——CVE-2026-21272—10.4%
——3——CVE-2025-12728—10.4%
——3——CVE-2026-2027—10.4%
——3——CVE-2024-39425—10.4%
——3——CVE-2026-343465.5 MED10.4%
——3Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.22dCVE-2025-54194—10.4%
——3——CVE-2026-164199.6 CRI10.4%
——3Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)20dCVE-2023-3112—10.4%
——3——CVE-2026-86768.8 HIG10.4%
——3An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.21dCVE-2025-6462—10.4%
——3——CVE-2025-54190—10.4%
——3——CVE-2025-54191—10.4%
——3——CVE-2023-52938—10.4%
——3——CVE-2021-41202—10.4%
——3——CVE-2024-49709—10.4%
——3——CVE-2025-53701—10.4%
——3——