Vulnerabilities exploitable today
356,923in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,543
- High10,564
- Medium6,729
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-23036—9.3%
——3——CVE-2026-12471—9.3%
——3——CVE-2025-43770—9.3%
——3——CVE-2025-42960—9.3%
——3——CVE-2024-58054—9.3%
——3——CVE-2022-20717—9.3%
——3——CVE-2019-2243—9.3%
——3——CVE-2026-1757—9.3%
——3——CVE-2026-178466.5 MED9.3%
——3Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)7dCVE-2022-36832—9.3%
——3——CVE-2022-49757—9.3%
——3——CVE-2024-51635—9.3%
——3——CVE-2026-178546.5 MED9.3%
——3Insufficient policy enforcement in WebMCP in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)7dCVE-2021-47415—9.3%
——3——CVE-2026-655167.2 HIG9.3%
——3Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.18dCVE-2023-53712—9.3%
——3——CVE-2025-49573—9.3%
——3——CVE-2026-3824—9.3%
——3——CVE-2026-595527.2 HIG9.3%
——3Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.14dCVE-2024-54407—9.3%
——3——CVE-2024-43684—9.3%
——3——CVE-2023-21125—9.3%
——3——CVE-2026-112378.3 HIG9.3%
——3Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)18dCVE-2024-54400—9.3%
——3——CVE-2024-43791—9.3%
——3——CVE-2024-22235—9.3%
——3——CVE-2026-23545—9.3%
——3——CVE-2022-34380—9.3%
——3——CVE-2021-47420—9.3%
——3——CVE-2026-1835—9.3%
——3——CVE-2026-0868—9.3%
——3——CVE-2026-206856.5 MED9.3%
——3An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.41dCVE-2024-50533—9.3%
——3——CVE-2021-47417—9.3%
——3——CVE-2025-7028—9.3%
——3——CVE-2025-48263—9.3%
——3——CVE-2026-23965—9.3%
——3——CVE-2023-53106—9.3%
——3——CVE-2026-17848.8 HIG9.3%
——3The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.1dCVE-2026-28493—9.3%
——3——