Vulnerabilities exploitable today
355,213in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,523
- High9,111
- Medium7,331
- Low692
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-5993—6.9%
——2——CVE-2024-13115—6.9%
——2——CVE-2025-68777—6.9%
——2——CVE-2026-554645.4 MED6.9%
——2Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes arbitrary JavaScript when another user opens the asset detail page and clicks the link. This issue is fixed in version 8.6.2.22dCVE-2026-39423—6.9%
——2——CVE-2026-56063—6.9%
——2——CVE-2026-100128.3 HIG6.9%
——2Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)14dCVE-2026-99907.5 HIG6.9%
——2Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)14dCVE-2025-67750—6.9%
——2——CVE-2026-99988.3 HIG6.9%
——2Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)14dCVE-2024-38591—6.9%
——2——CVE-2024-38432—6.9%
——2——CVE-2017-6263—6.9%
——2——CVE-2025-23233—6.9%
——2——CVE-2025-62076—6.9%
——2——CVE-2021-37686—6.9%
——2——CVE-2023-54247—6.9%
——2——CVE-2025-59900—6.9%
——2——CVE-2024-45019—6.9%
——2——CVE-2025-59897—6.9%
——2——CVE-2026-94905.5 MED6.9%
——2A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe, causing the service to crash with exit code 1067 (ERROR_PROCESS_ABORTED). To mitigate this potential local service disruption, Acer requires users to update the software to the latest version.12dCVE-2023-40155—6.9%
——2——CVE-2025-10567—6.9%
——2——CVE-2026-32446—6.9%
——2——CVE-2023-54074—6.9%
——2——CVE-2025-68804—6.9%
——2——CVE-2025-23675—6.9%
——2——CVE-2025-379087.8 HIG6.9%
——2In the Linux kernel, the following vulnerability has been resolved:
mm, slab: clean up slab->obj_exts always
When memory allocation profiling is disabled at runtime or due to an
error, shutdown_mem_profiling() is called: slab->obj_exts which
previously allocated remains.
It won't be cleared by unaccount_slab() because of
mem_alloc_profiling_enabled() not true. It's incorrect, slab->obj_exts
should always be cleaned up in unaccount_slab() to avoid following error:
[...]BUG: Bad page state in process...
..
[...]page dumped because: page still charged to cgroup
[andriy.shevchenko@linux.intel.com: fold need_slab_obj_ext() into its only user]5dCVE-2023-54154—6.9%
——2——CVE-2025-31975—6.9%
——2——CVE-2025-15313—6.9%
——2——CVE-2025-47871—6.9%
——2——CVE-2022-42839—6.9%
——2——CVE-2023-54144—6.9%
——2——CVE-2025-68821—6.9%
——2——CVE-2023-54188—6.9%
——2——CVE-2022-50301—6.9%
——2——CVE-2024-22383—6.9%
——2——CVE-2024-43337—6.9%
——2——CVE-2026-64345—6.9%
——2In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_printer: take kref only for successful open
printer_open() returns -EBUSY when the character device is already
open, but it increments dev->kref regardless of the return value. VFS
does not call ->release() for a failed open, so every rejected second
open permanently leaks one reference.
Move kref_get() into the successful-open branch.10d