Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,699
- High11,582
- Medium7,301
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-25776—10.4%
——3——CVE-2026-164427.4 HIG10.4%
——3A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.3dCVE-2025-49940—10.4%
——3——CVE-2025-62741—10.4%
——3——CVE-2026-24388—10.4%
——3——CVE-2026-157937.5 HIG10.4%
——3BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.14dCVE-2025-42945—10.4%
——3——CVE-2022-27609—10.4%
——3——CVE-2021-20260—10.4%
——3——CVE-2025-54128—10.4%
——3——CVE-2023-24491—10.4%
——3——CVE-2026-82364.3 MED10.4%
——3Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns internal site structure data (page IDs, versions, URL paths) to anyone who sends a GET request. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.21dCVE-2026-116447.5 HIG10.4%
——3Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)21dCVE-2022-50172—10.4%
——3——CVE-2025-42914—10.4%
——3——CVE-2026-144138.3 HIG10.4%
——3Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)41dCVE-2018-11265—10.4%
——3——CVE-2025-0672—10.4%
——3——CVE-2025-43837—10.4%
——3——CVE-2022-49732—10.4%
——3——CVE-2026-111326.5 MED10.4%
——3Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)21dCVE-2022-50184—10.4%
——3——CVE-2025-12535—10.4%
——3——CVE-2023-41519—10.3%
——3——CVE-2022-22270—10.4%
——3——CVE-2018-11298—10.4%
——3——CVE-2025-43924—10.4%
——3——CVE-2022-50653—10.4%
——3——CVE-2022-50645—10.4%
——3——CVE-2025-62024—10.4%
——3——CVE-2022-49983—10.4%
——3——CVE-2024-0179—10.4%
——3——CVE-2020-11199—10.4%
——3——CVE-2019-25279—10.4%
——3——CVE-2024-45104—10.4%
——3——CVE-2022-50039—10.4%
——3——CVE-2025-43839—10.4%
——3——CVE-2024-0155—10.4%
——3——CVE-2025-50733—10.4%
——3——CVE-2025-31500—10.4%
——3——