Vulnerabilities exploitable today
356,679in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,534
- High10,642
- Medium6,742
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-503858.8 HIG8.1%
——2Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.17dCVE-2026-504277.8 HIG8.1%
——2Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.17dCVE-2025-21688—8.1%
——2——CVE-2025-64736—8.1%
——2——CVE-2023-4028—8.1%
——2——CVE-2026-8561—8.1%
——2——CVE-2022-41749—8.1%
——2——CVE-2026-25306—8.1%
——2——CVE-2026-30979—8.1%
——2——CVE-2026-504577.8 HIG8.1%
——2Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.17dCVE-2022-42276—8.1%
——2——CVE-2025-2630—8.1%
——2——CVE-2026-648807.1 HIG8.1%
——2Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.17dCVE-2022-23817—8.1%
——2——CVE-2023-34419—8.1%
——2——CVE-2025-38037—8.1%
——2——CVE-2025-2629—8.1%
——2——CVE-2023-4029—8.1%
——2——CVE-2024-38864—8.1%
——2——CVE-2024-2313—8.1%
——2——CVE-2026-12450—8.1%
——2——CVE-2025-20117—8.1%
——2——CVE-2026-42341—8.1%
——2FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment, by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds are available. Disable the Custom payment gateway if not actively needed and/or restrict access to `/ipn.php` at the web server level (e.g., via IP allowlisting), noting that this may interfere with legitimate payment callback processing.32dCVE-2026-541257.8 HIG8.1%
——2Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.18dCVE-2024-51440—8.1%
——2——CVE-2022-49962—8.1%
——2——CVE-2024-34367—8.1%
——2——CVE-2024-31105—8.1%
——2——CVE-2022-34147—8.1%
——2——CVE-2024-56666—8.1%
——2——CVE-2021-3722—8.1%
——2——CVE-2025-25183—8.1%
——2——CVE-2024-51225—8.1%
——2——CVE-2025-25329—8.1%
——2——CVE-2026-177345.4 MED8.1%
——2Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)9dCVE-2025-46276—8.1%
——2——CVE-2025-25326—8.1%
——2——CVE-2024-31285—8.1%
——2——CVE-2026-31989—8.1%
——2——CVE-2026-26276—8.1%
——2——