Vulnerabilities exploitable today
354,449in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,641
- High9,461
- Medium7,690
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-46897—4.5%
——1——CVE-2022-50490—4.5%
——1——CVE-2022-49774—4.5%
——1——CVE-2023-53486—4.5%
——1——CVE-2025-9880—4.5%
——1——CVE-2022-50255—4.5%
——1——CVE-2025-37762—4.5%
——1——CVE-2025-0884—4.5%
——1——CVE-2022-50417—4.5%
——1——CVE-2023-22592—4.5%
——1——CVE-2022-50507—4.5%
——1——CVE-2025-47473—4.5%
——1——CVE-2026-11604—4.5%
——1An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).8dCVE-2023-25521—4.5%
——1——CVE-2020-27037—4.5%
——1——CVE-2021-22417—4.5%
——1——CVE-2021-22365—4.5%
——1——CVE-2025-11547—4.5%
——1——CVE-2023-53017—4.5%
——1——CVE-2026-112435.4 MED4.5%
——1Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)8dCVE-2026-655385.9 MED4.5%
——1Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.7dCVE-2025-57915—4.5%
——1——CVE-2025-52627—4.5%
——1——CVE-2025-57930—4.5%
——1——CVE-2020-36790—4.5%
——1——CVE-2025-14979—4.5%
——1——CVE-2022-49810—4.5%
——1——CVE-2023-53420—4.5%
——1——CVE-2025-7073—4.5%
——1——CVE-2022-49833—4.5%
——1——CVE-2022-50522—4.5%
——1——CVE-2022-49901—4.5%
——1——CVE-2020-24682—4.5%
——1——CVE-2022-49858—4.5%
——1——CVE-2021-22318—4.5%
——1——CVE-2023-53018—4.5%
——1——CVE-2026-49839—4.5%
——1——CVE-2026-56392—4.5%
——1GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.
When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.
When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.
This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d10hCVE-2026-45894—4.5%
——1——CVE-2022-49773—4.5%
——1——