Vulnerabilities exploitable today
354,470in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,643
- High9,463
- Medium7,694
- Low694
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-25286—4.7%
——1——CVE-2025-34424—4.7%
——1——CVE-2021-4460—4.7%
——1——CVE-2020-0129—4.7%
——1——CVE-2026-423117.8 HIG4.7%
——1Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.7dCVE-2016-20047—4.7%
——1——CVE-2023-53494—4.7%
——1——CVE-2025-0893—4.7%
——1——CVE-2026-6383—4.7%
——1——CVE-2026-56823—4.7%
——1——CVE-2023-4753—4.7%
——1——CVE-2023-29151—4.7%
——1——CVE-2026-58936.8 MED4.7%
——1Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)7dCVE-2026-437728.2 HIG4.7%
——1A path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.3dCVE-2025-25123—4.7%
——1——CVE-2025-463075.5 MED4.7%
——1A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.8dCVE-2019-2026—4.7%
——1——CVE-2020-37055—4.7%
——1——CVE-2025-13327—4.7%
——1——CVE-2016-4984—4.7%
——1——CVE-2020-37047—4.7%
——1——CVE-2023-53282—4.7%
——1——CVE-2024-21784—4.7%
——1——CVE-2020-10053—4.7%
——1——CVE-2024-6364—4.7%
——1——CVE-2020-37062—4.7%
——1——CVE-2025-34419—4.7%
——1——CVE-2025-20338—4.7%
——1——CVE-2020-0166—4.7%
——1——CVE-2023-27975—4.7%
——1——CVE-2022-50505—4.7%
——1——CVE-2022-50448—4.7%
——1——CVE-2026-410475.5 MED4.7%
——1Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.24dCVE-2022-43456—4.7%
——1——CVE-2025-24296—4.7%
——1——CVE-2025-38208—4.7%
——1——CVE-2025-25072—4.7%
——1——CVE-2025-397618.8 HIG4.7%
——1In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: Decrement TID on RX peer frag setup error handling
Currently, TID is not decremented before peer cleanup, during error
handling path of ath12k_dp_rx_peer_frag_setup(). This could lead to
out-of-bounds access in peer->rx_tid[].
Hence, add a decrement operation for TID, before peer cleanup to
ensures proper cleanup and prevents out-of-bounds access issues when
the RX peer frag setup fails.
Found during code review. Compile tested only.1dCVE-2026-46055—4.7%
——1——CVE-2025-71306—4.7%
——1——