Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,699
- High11,582
- Medium7,301
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-0179—10.4%
——3——CVE-2022-50039—10.4%
——3——CVE-2025-0672—10.4%
——3——CVE-2025-43837—10.4%
——3——CVE-2024-579857.0 HIG10.4%
——3In the Linux kernel, the following vulnerability has been resolved:
firmware: qcom: scm: Cleanup global '__scm' on probe failures
If SCM driver fails the probe, it should not leave global '__scm'
variable assigned, because external users of this driver will assume the
probe finished successfully. For example TZMEM parts ('__scm->mempool')
are initialized later in the probe, but users of it (__scm_smc_call())
rely on the '__scm' variable.
This fixes theoretical NULL pointer exception, triggered via introducing
probe deferral in SCM driver with call trace:
qcom_tzmem_alloc+0x70/0x1ac (P)
qcom_tzmem_alloc+0x64/0x1ac (L)
qcom_scm_assign_mem+0x78/0x194
qcom_rmtfs_mem_probe+0x2d4/0x38c
platform_probe+0x68/0xc89dCVE-2023-41529—10.3%
——3——CVE-2026-111326.5 MED10.4%
——3Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)21dCVE-2024-35203—10.4%
——3——CVE-2026-180159.6 CRI10.4%
——3Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)9dCVE-2023-53799—10.4%
——3——CVE-2023-39943—10.4%
——3——CVE-2025-43836—10.4%
——3——CVE-2023-40009—10.4%
——3——CVE-2025-31500—10.4%
——3——CVE-2022-48854—10.4%
——3——CVE-2023-32432—10.4%
——3——CVE-2025-54800—10.4%
——3——CVE-2025-31501—10.4%
——3——CVE-2025-39203—10.4%
——3——CVE-2025-27006—10.4%
——3——CVE-2020-0133—10.4%
——3——CVE-2025-59825—10.4%
——3——CVE-2018-16261—10.4%
——3——CVE-2022-41183—10.4%
——3——CVE-2025-714007.1 HIG10.4%
——3better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys.10dCVE-2024-29093—10.4%
——3——CVE-2024-1440—10.4%
——3——CVE-2024-13954—10.4%
——3——CVE-2025-55112—10.4%
——3——CVE-2025-62024—10.4%
——3——CVE-2022-49983—10.4%
——3——CVE-2022-50645—10.4%
——3——CVE-2026-164427.4 HIG10.4%
——3A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.3dCVE-2025-6140—10.4%
——3——CVE-2024-3076—10.4%
——3——CVE-2026-111336.5 MED10.4%
——3Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)21dCVE-2024-467307.8 HIG10.4%
——3In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Ensure array index tg_inst won't be -1
[WHY & HOW]
tg_inst will be a negative if timing_generator_count equals 0, which
should be checked before used.
This fixes 2 OVERRUN issues reported by Coverity.9dCVE-2025-62027—10.4%
——3——CVE-2025-42913—10.4%
——3——CVE-2023-25776—10.4%
——3——