Vulnerabilities exploitable today
355,017in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,558
- High9,191
- Medium7,449
- Low695
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-27408—6.5%
——2——CVE-2026-242477.8 HIG6.5%
——2NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.32dCVE-2026-179724.3 MED6.5%
——2Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)4dCVE-2026-151244.3 MED6.5%
——2Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)25dCVE-2024-35798—6.5%
——2——CVE-2026-148212.7 LOW6.5%
——2The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.6dCVE-2026-26979—6.5%
——2——CVE-2023-54041—6.5%
——2——CVE-2022-22079—6.5%
——2——CVE-2023-28059—6.5%
——2——CVE-2022-50142—6.5%
——2——CVE-2022-31641—6.5%
——2——CVE-2026-179654.3 MED6.5%
——2Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)4dCVE-2022-0915—6.5%
——2——CVE-2022-31640—6.5%
——2——CVE-2023-28056—6.5%
——2——CVE-2026-57958—6.5%
——2——CVE-2025-14875—6.5%
——2——CVE-2024-11268—6.5%
——2——CVE-2026-23566—6.5%
——2——CVE-2023-28042—6.5%
——2——CVE-2023-28035—6.5%
——2——CVE-2023-28030—6.5%
——2——CVE-2023-28029—6.5%
——2——CVE-2026-28826—6.5%
——2——CVE-2026-115782.7 LOW6.5%
——2The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default configuration in which an administrator has created at least one Manager restricted to specific forms.32dCVE-2026-179554.3 MED6.5%
——2Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)4dCVE-2023-28034—6.5%
——2——CVE-2022-30297—6.5%
——2——CVE-2022-3744—6.5%
——2——CVE-2023-28031—6.5%
——2——CVE-2024-37163—6.5%
——2——CVE-2023-28050—6.5%
——2——CVE-2023-28054—6.5%
——2——CVE-2021-1889—6.5%
——2——CVE-2022-50097—6.5%
——2——CVE-2023-28028—6.5%
——2——CVE-2024-35122—6.5%
——2——CVE-2025-71240—6.5%
——2——CVE-2026-179454.3 MED6.5%
——2Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)4d