Vulnerabilities exploitable today
354,470in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,643
- High9,463
- Medium7,694
- Low694
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-1963—4.6%
——1——CVE-2026-46423—4.6%
——1——CVE-2025-38312—4.6%
——1——CVE-2025-46373—4.6%
——1——CVE-2025-26330—4.6%
——1——CVE-2025-38195—4.6%
——1——CVE-2024-39580—4.6%
——1——CVE-2025-5454—4.6%
——1——CVE-2020-36652—4.6%
——1——CVE-2026-559854.3 MED4.6%
——1The web management interface in
Tycon Systems TPDIN-Monitor-WEB2
stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.17hCVE-2020-37048—4.6%
——1——CVE-2025-62776—4.6%
——1——CVE-2026-21437—4.6%
——1——CVE-2025-61993.3 LOW4.6%
——1A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.31dCVE-2026-1446—4.6%
——1——CVE-2026-489056.1 MED4.6%
——1Lack of input filtering leads to an XSS vector in the HTML filter code.10dCVE-2026-02377.8 HIG4.6%
——1An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.17dCVE-2026-133186.4 MED4.6%
——1A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and passes it directly to net.Dial() without validation. For VMIs using non-masquerade network bindings (bridge or secondary-only), this IP is reported by the QEMU guest agent running inside the VM and is fully controllable by the VM owner. An attacker with kubevirt.io:edit permissions can create a VM with a modified guest agent that reports an arbitrary IP address, then request port-forward to establish a bidirectional TCP tunnel from virt-api's cluster-internal network position to any routable destination, bypassing NetworkPolicy isolation.25dCVE-2025-20094—4.6%
——1——CVE-2024-20869—4.6%
——1——CVE-2025-39685—4.6%
——1——CVE-2026-32755—4.6%
——1——CVE-2025-57846—4.6%
——1——CVE-2020-37037—4.6%
——1——CVE-2020-9210—4.6%
——1——CVE-2023-53219—4.6%
——1——CVE-2025-68890—4.6%
——1——CVE-2026-437237.8 HIG4.6%
——1A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.2dCVE-2026-43492—4.6%
——1——CVE-2025-31572—4.6%
——1——CVE-2025-59730—4.6%
——1——CVE-2026-25369—4.6%
——1——CVE-2024-45070—4.6%
——1——CVE-2021-37000—4.6%
——1——CVE-2024-46872—4.6%
——1——CVE-2020-0296—4.6%
——1——CVE-2023-38640—4.6%
——1——CVE-2023-41821—4.6%
——1——CVE-2025-59729—4.6%
——1——CVE-2026-141334.2 MED4.6%
——1Race in History Embeddings in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)30d