Vulnerabilities exploitable today
356,659in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,544
- High10,730
- Medium6,917
- Low695
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-20094—7.9%
——2——CVE-2025-55054—7.9%
——2——CVE-2025-23749—7.9%
——2——CVE-2025-59763—7.9%
——2——CVE-2025-68936—7.9%
——2——CVE-2026-139295.5 MED7.9%
——2Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium)38dCVE-2025-30440—7.9%
——2——CVE-2025-60932—7.9%
——2——CVE-2022-31476—7.9%
——2——CVE-2025-60933—7.9%
——2——CVE-2025-63946—7.9%
——2——CVE-2025-37932—7.9%
——2——CVE-2025-24756—7.9%
——2——CVE-2026-02807.2 HIG7.9%
——2An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.
Cloud NGFW and Panorama are not impacted by this vulnerability.26dCVE-2024-55897—7.9%
——2——CVE-2025-23109—7.8%
——2——CVE-2026-419883.2 LOW7.9%
——2uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.31dCVE-2026-41487—7.9%
——2——CVE-2025-52580—7.9%
——2——CVE-2025-65472—7.9%
——2——CVE-2026-140816.5 MED7.9%
——2Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Low)38dCVE-2026-190613.7 LOW7.9%
——2A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.11hCVE-2026-115675.9 MED7.9%
——2The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. Forms using a fixed configured price are not affected.25dCVE-2025-59764—7.9%
——2——CVE-2026-27679—7.9%
——2——CVE-2026-27678—7.9%
——2——CVE-2025-59767—7.9%
——2——CVE-2025-23743—7.9%
——2——CVE-2025-59768—7.9%
——2——CVE-2026-586287.8 HIG7.9%
——2Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.17dCVE-2024-8270—7.9%
——2——CVE-2026-21907—7.9%
——2——CVE-2026-42729—7.9%
——2——CVE-2026-112368.3 HIG7.9%
——2Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)16dCVE-2026-42728—7.9%
——2——CVE-2021-41217—7.9%
——2——CVE-2025-59771—7.9%
——2——CVE-2025-59765—7.9%
——2——CVE-2026-33092—7.9%
——2——CVE-2025-12001—7.9%
——2——