Vulnerabilities exploitable today
356,659in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,544
- High10,730
- Medium6,917
- Low695
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-12986—7.8%
——2——CVE-2025-48884—7.9%
——2——CVE-2025-12001—7.9%
——2——CVE-2025-52647—7.9%
——2——CVE-2025-59751—7.9%
——2——CVE-2025-30440—7.9%
——2——CVE-2025-38323—7.9%
——2——CVE-2025-59750—7.9%
——2——CVE-2025-24756—7.9%
——2——CVE-2025-22839—7.9%
——2——CVE-2023-30693—7.9%
——2——CVE-2024-4429—7.9%
——2——CVE-2025-30923—7.9%
——2——CVE-2026-37216—7.8%
——2——CVE-2025-40177—7.8%
——2——CVE-2026-1924—7.8%
——2——CVE-2025-46702—7.8%
——2——CVE-2025-11800—7.8%
——2——CVE-2024-23980—7.8%
——2——CVE-2026-141535.3 MED7.8%
——2Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)38dCVE-2021-46987—7.8%
——2——CVE-2024-36028—7.8%
——2——CVE-2025-12715—7.8%
——2——CVE-2026-41575—7.8%
——2——CVE-2022-45126—7.8%
——2——CVE-2022-49576—7.8%
——2——CVE-2023-39986—7.8%
——2——CVE-2026-546636.1 MED7.8%
——2swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl to fetch any http or https target without private IP, redirect, DNS rebinding, or same-origin validation, allowing an attacker-controlled OpenAPI spec to make the generator issue requests to internal or link-local services. This issue is fixed in version 13.12.2.9dCVE-2025-12804—7.8%
——2——CVE-2024-386287.8 HIG7.8%
——2In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind.
Hang on to the control IDs instead of pointers since those are correctly
handled with locks.4dCVE-2024-51454—7.8%
——2——CVE-2025-43465—7.8%
——2——CVE-2025-13054—7.8%
——2——CVE-2026-107706.1 MED7.8%
——2Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1.2dCVE-2026-40336—7.8%
——2——CVE-2025-11764—7.8%
——2——CVE-2026-179014.3 MED7.8%
——2Insufficient validation of untrusted input in Sharing in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Low)5dCVE-2025-65136—7.8%
——2——CVE-2024-46793—7.8%
——2——CVE-2026-42572—7.8%
——2——