Vulnerabilities exploitable today
358,921in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,711
- High11,665
- Medium7,447
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-64829—9.9%
——3——CVE-2024-55059—9.9%
——3——CVE-2025-37766—9.9%
——3——CVE-2025-40031—9.9%
——3——CVE-2023-21281—9.9%
——3——CVE-2020-9091—9.9%
——3——CVE-2026-02707.5 HIG9.9%
——3A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.21dCVE-2019-10580—9.9%
——3——CVE-2026-32395—9.9%
——3——CVE-2023-30714—9.9%
——3——CVE-2020-9095—9.9%
——3——CVE-2019-14099—9.9%
——3——CVE-2025-46713—9.9%
——3——CVE-2025-30987—9.9%
——3——CVE-2024-56997—9.9%
——3——CVE-2025-64850—9.9%
——3——CVE-2026-99425.0 MED9.9%
——3Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)23dCVE-2024-45182—9.9%
——3——CVE-2025-64853—9.9%
——3——CVE-2022-50635—9.9%
——3——CVE-2026-34341—9.9%
——3——CVE-2026-712368.7 HIG9.9%
——3Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &lt;, &gt;, and &amp; back to <, >, and & immediately after purification.3dCVE-2025-0033—9.9%
——3——CVE-2026-32413—9.9%
——3——CVE-2025-63442—9.9%
——3——CVE-2024-8067—9.9%
——3——CVE-2025-11874—9.9%
——3——CVE-2022-28656—9.9%
——3——CVE-2019-14124—9.9%
——3——CVE-2025-64582—9.9%
——3——CVE-2022-502137.8 HIG9.9%
——3In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: do not allow SET_ID to refer to another table
When doing lookups for sets on the same batch by using its ID, a set from a
different table can be used.
Then, when the table is removed, a reference to the set may be kept after
the set is freed, leading to a potential use-after-free.
When looking for sets by ID, use the table that was used for the lookup by
name, and only return sets belonging to that same table.
This fixes CVE-2022-2586, also reported as ZDI-CAN-17470.9dCVE-2025-64574—9.9%
——3——CVE-2025-64600—9.9%
——3——CVE-2025-64861—9.9%
——3——CVE-2023-49125—9.9%
——3——CVE-2026-491627.0 HIG9.9%
——3Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.22dCVE-2025-40057—9.9%
——3——CVE-2019-14037—9.9%
——3——CVE-2025-40037—9.9%
——3——CVE-2022-42793—9.9%
——3——