Vulnerabilities exploitable today
354,867in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,555
- High9,167
- Medium7,432
- Low691
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-53358—6.1%
——2——CVE-2025-34180—6.1%
——2——CVE-2024-235704.3 MED6.1%
——2HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.16dCVE-2023-53124—6.1%
——2——CVE-2026-100046.5 MED6.1%
——2Insufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)12dCVE-2025-44021—6.1%
——2——CVE-2023-53765—6.1%
——2——CVE-2026-44659—6.1%
——2——CVE-2026-242497.8 HIG6.1%
——2NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.31dCVE-2025-37818—6.1%
——2——CVE-2024-34595—6.1%
——2——CVE-2026-32891—6.1%
——2——CVE-2025-37790—6.1%
——2——CVE-2023-53750—6.1%
——2——CVE-2025-6241—6.1%
——2——CVE-2024-11263—6.1%
——2——CVE-2025-38109—6.1%
——2——CVE-2025-4198—6.1%
——2——CVE-2024-20832—6.1%
——2——CVE-2024-9450—6.1%
——2——CVE-2026-551447.1 HIG6.1%
——2Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.12dCVE-2023-53816—6.1%
——2——CVE-2025-38185—6.1%
——2——CVE-2025-41392—6.1%
——2——CVE-2025-4424—6.1%
——2——CVE-2025-6923—6.1%
——2——CVE-2025-40287—6.1%
——2——CVE-2022-50033—6.1%
——2——CVE-2024-42253—6.1%
——2——CVE-2022-48941—6.1%
——2——CVE-2023-53121—6.1%
——2——CVE-2025-20881—6.1%
——2——CVE-2026-131267.8 HIG6.1%
——2The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.24dCVE-2024-12709—6.1%
——2——CVE-2024-36944—6.1%
——2——CVE-2023-52947—6.1%
——2——CVE-2022-49916—6.1%
——2——CVE-2026-45855—6.1%
——2——CVE-2017-15854—6.1%
——2——CVE-2026-32164—6.1%
——2——