Vulnerabilities exploitable today
356,923in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,543
- High10,564
- Medium6,729
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-52615—9.3%
——3——CVE-2025-8103—9.3%
——3——CVE-2026-59108.8 HIG9.3%
——3Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)17dCVE-2024-7574—9.3%
——3——CVE-2025-51736—9.3%
——3——CVE-2025-40902—9.3%
——3——CVE-2025-22097—9.3%
——3——CVE-2026-59098.8 HIG9.3%
——3Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)17dCVE-2022-48189—9.3%
——3——CVE-2024-37511—9.3%
——3——CVE-2024-37543—9.3%
——3——CVE-2025-47128—9.3%
——3——CVE-2022-48681—9.3%
——3——CVE-2026-8538—9.3%
——3——CVE-2026-62659—9.3%
——3A
security flaw was discovered in the NETGEAR WAX333 Access Point that could
allow someone already logged in and connected to the local network to make
unauthorized changes to the device's settings26dCVE-2024-4867—9.3%
——3——CVE-2025-40903—9.3%
——3——CVE-2023-30651—9.3%
——3——CVE-2024-37490—9.3%
——3——CVE-2019-10495—9.3%
——3——CVE-2026-9259—9.3%
——3——CVE-2025-63927—9.3%
——3——CVE-2025-64784—9.3%
——3——CVE-2024-37493—9.3%
——3——CVE-2024-37491—9.3%
——3——CVE-2026-23029—9.3%
——3——CVE-2026-59180—9.3%
——3——CVE-2025-53627—9.3%
——3——CVE-2025-43742—9.3%
——3——CVE-2026-122527.8 HIG9.3%
——3In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes accept user-controllable JAR paths and execute them via the `java()` function, which invokes `subprocess.Popen()` without integrity verification. This vulnerability is identical to CVE-2026-0848, which was fixed for StanfordSegmenter by adding SHA256 verification. However, the fix was not applied to these additional classes, leaving them susceptible to arbitrary code execution when loading untrusted JAR files.33dCVE-2025-9908—9.3%
——3——CVE-2024-47039—9.3%
——3——CVE-2026-42746—9.3%
——3——CVE-2026-23028—9.3%
——3——CVE-2024-53071—9.3%
——3——CVE-2023-43741—9.3%
——3——CVE-2026-23039—9.3%
——3——CVE-2024-37240—9.3%
——3——CVE-2024-37478—9.3%
——3——CVE-2026-20209—9.3%
——3——