Vulnerabilities exploitable today
356,768in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,533
- High10,540
- Medium6,708
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-12016—9.0%
——3——CVE-2024-21788—9.0%
——3——CVE-2025-47751—9.0%
——3——CVE-2018-13013—9.0%
——3——CVE-2026-11597—9.0%
——3——CVE-2025-47753—9.0%
——3——CVE-2026-12681—9.0%
——3——CVE-2025-47757—9.0%
——3——CVE-2026-139924.2 MED9.0%
——3Inappropriate implementation in UI in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)40dCVE-2025-63052—9.0%
——3——CVE-2023-24591—9.0%
——3——CVE-2025-12184—9.0%
——3——CVE-2025-12631—9.0%
——3——CVE-2023-28907—9.0%
——3——CVE-2025-12065—9.0%
——3——CVE-2024-22335—9.0%
——3——CVE-2025-67543—9.0%
——3——CVE-2025-47752—9.0%
——3——CVE-2023-29161—9.0%
——3——CVE-2024-48542—9.0%
——3——CVE-2025-67550—9.0%
——3——CVE-2022-34454—9.0%
——3——CVE-2026-139734.2 MED9.0%
——3Inappropriate implementation in UI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)40dCVE-2018-11274—9.0%
——3——CVE-2022-23000—9.0%
——3——CVE-2024-27717—9.0%
——3——CVE-2025-47754—9.0%
——3——CVE-2023-41091—9.0%
——3——CVE-2018-25336—9.0%
——3——CVE-2024-52270—9.0%
——3——CVE-2026-648778.4 HIG9.0%
——3An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.17dCVE-2025-31965—9.0%
——3——CVE-2025-47818—9.0%
——3——CVE-2023-28388—9.0%
——3——CVE-2023-25075—9.0%
——3——CVE-2025-20030—9.0%
——3——CVE-2025-64261—9.0%
——3——CVE-2025-396987.8 HIG9.0%
——3In the Linux kernel, the following vulnerability has been resolved:
io_uring/futex: ensure io_futex_wait() cleans up properly on failure
The io_futex_data is allocated upfront and assigned to the io_kiocb
async_data field, but the request isn't marked with REQ_F_ASYNC_DATA
at that point. Those two should always go together, as the flag tells
io_uring whether the field is valid or not.
Additionally, on failure cleanup, the futex handler frees the data but
does not clear ->async_data. Clear the data and the flag in the error
path as well.
Thanks to Trend Micro Zero Day Initiative and particularly ReDress for
reporting this.11dCVE-2026-406395.7 MED9.0%
——3Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.18dCVE-2024-25030—9.0%
——3——