Vulnerabilities exploitable today
354,630in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,600
- High9,389
- Medium7,532
- Low703
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-22613—5.1%
——2——CVE-2021-33658—5.1%
——2——CVE-2025-58870—5.1%
——2——CVE-2024-21769—5.1%
——2——CVE-2025-39914—5.1%
——2——CVE-2024-20901—5.1%
——2——CVE-2026-272957.8 HIG5.1%
——2Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.6dCVE-2025-58987—5.1%
——2——CVE-2026-32883—5.1%
——2——CVE-2025-58632—5.1%
——2——CVE-2025-62974—5.1%
——2——CVE-2025-58863—5.1%
——2——CVE-2025-58985—5.1%
——2——CVE-2026-616435.9 MED5.1%
——2FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that points to another user's private HTTP toolset by using a crafted saved tool id such as http-<victim_toolset_app_id>/<tool_name>. The normal toolset routes deny access, but the workflow save and runtime path did not apply the same authorization check to the referenced toolset, allowing /api/v2/chat/completions to resolve the saved reference and execute the victim-owned HTTP tool. This issue is fixed in version 4.15.0-beta5.11dCVE-2025-64362—5.1%
——2——CVE-2025-48103—5.1%
——2——CVE-2025-58864—5.1%
——2——CVE-2025-38222—5.1%
——2——CVE-2025-23378—5.1%
——2——CVE-2025-58988—5.1%
——2——CVE-2026-355337.7 HIG5.1%
——2mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and then reach dangerous directives such as [env] _.source, templates, hooks, or tasks.7dCVE-2025-58989—5.1%
——2——CVE-2025-62984—5.1%
——2——CVE-2025-25074—5.1%
——2——CVE-2026-27151—5.1%
——2——CVE-2022-39861—5.1%
——2——CVE-2025-63010—5.1%
——2——CVE-2025-64365—5.1%
——2——CVE-2023-21458—5.1%
——2——CVE-2025-62969—5.1%
——2——CVE-2025-62968—5.1%
——2——CVE-2021-37673—5.1%
——2——CVE-2025-58997—5.1%
——2——CVE-2021-0924—5.1%
——2——CVE-2018-9581—5.1%
——2——CVE-2024-20881—5.1%
——2——CVE-2025-64367—5.1%
——2——CVE-2025-48088—5.1%
——2——CVE-2026-113004.3 MED5.1%
——2Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)9dCVE-2026-139553.3 LOW5.1%
——2Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Medium)29d