Vulnerabilities exploitable today
354,630in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,600
- High9,389
- Medium7,532
- Low703
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-21458—5.1%
——2——CVE-2021-37673—5.1%
——2——CVE-2025-62967—5.1%
——2——CVE-2025-400677.8 HIG5.1%
——2In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: reject index allocation if $BITMAP is empty but blocks exist
Index allocation requires at least one bit in the $BITMAP attribute to
track usage of index entries. If the bitmap is empty while index blocks
are already present, this reflects on-disk corruption.
syzbot triggered this condition using a malformed NTFS image. During a
rename() operation involving a long filename (which spans multiple
index entries), the empty bitmap allowed the name to be added without
valid tracking. Subsequent deletion of the original entry failed with
-ENOENT, due to unexpected index state.
Reject such cases by verifying that the bitmap is not empty when index
blocks exist.2dCVE-2021-30268—5.1%
——2——CVE-2025-38414—5.1%
——2——CVE-2026-112284.3 MED5.1%
——2Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)9dCVE-2025-48103—5.1%
——2——CVE-2025-64354—5.1%
——2——CVE-2025-62985—5.1%
——2——CVE-2021-34564—5.1%
——2——CVE-2023-28823—5.1%
——2——CVE-2026-22798—5.1%
——2——CVE-2025-58626—5.1%
——2——CVE-2025-38369—5.1%
——2——CVE-2023-34355—5.1%
——2——CVE-2026-151108.8 HIG5.1%
——2Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)22dCVE-2025-22705—5.1%
——2——CVE-2023-22841—5.1%
——2——CVE-2025-58880—5.1%
——2——CVE-2025-58868—5.1%
——2——CVE-2025-58867—5.1%
——2——CVE-2026-47715—5.1%
——2——CVE-2026-585805.9 MED5.1%
——2LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows by message id alone, omitting the userId scope that sibling methods apply, and findMessagePlugin reads back by id alone. Reachable via the corresponding tRPC message procedures, an authenticated user who knows another user's message identifier can overwrite that victim's plugin tool-call metadata, plugin state/error, text-to-speech and translation records on the same instance, and the tampered content is served back to the victim. Exploitation requires knowledge of the victim's non-enumerable message identifier.17dCVE-2025-64220—5.1%
——2——CVE-2024-52065—5.1%
——2——CVE-2026-33384—5.1%
——2QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID
for a victim and later hijack the authenticated session.
This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable.10dCVE-2026-20451—5.1%
——2——CVE-2025-58874—5.1%
——2——CVE-2025-58870—5.1%
——2——CVE-2024-23491—5.1%
——2——CVE-2026-272957.8 HIG5.1%
——2Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.6dCVE-2025-58876—5.1%
——2——CVE-2025-58875—5.1%
——2——CVE-2026-32883—5.1%
——2——CVE-2023-23577—5.1%
——2——CVE-2025-64202—5.1%
——2——CVE-2024-52064—5.1%
——2——CVE-2025-64208—5.1%
——2——CVE-2025-38163—5.1%
——2——