Vulnerabilities exploitable today
352,969in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,334
- High8,050
- Medium7,230
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-12415—3.9%
——1——CVE-2025-43935—3.9%
——1——CVE-2025-12406—3.9%
——1——CVE-2026-111264.3 MED3.9%
——1Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)5dCVE-2025-49877—3.9%
——1——CVE-2026-14899—3.9%
——1The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.5dCVE-2023-0192—3.9%
——1——CVE-2023-30730—3.9%
——1——CVE-2025-20689—3.9%
——1——CVE-2025-20690—3.9%
——1——CVE-2025-20691—3.9%
——1——CVE-2025-24313—3.9%
——1——CVE-2020-0208—3.9%
——1——CVE-2025-39836—3.9%
——1——CVE-2023-73437.8 HIG3.9%
——1Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vulnerability triggered when an administrator opens a maliciously crafted project file. Successful exploitation allows the attacker to execute code in the context of the HiVision process.3dCVE-2023-45864—3.9%
——1——CVE-2026-57456—3.9%
——1——CVE-2023-30565—3.9%
——1——CVE-2021-26734—3.9%
——1——CVE-2024-44956—3.9%
——1——CVE-2022-25743—3.9%
——1——CVE-2026-42144—3.9%
——1——CVE-2025-26403—3.9%
——1——CVE-2025-4276—3.9%
——1——CVE-2026-33887—3.9%
——1——CVE-2022-39904—3.9%
——1——CVE-2023-33053—3.9%
——1——CVE-2026-585596.5 MED3.9%
——1DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.12dCVE-2026-84098.8 HIG3.9%
——1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete. The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.4dCVE-2026-31772—3.9%
——1——CVE-2024-13960—3.9%
——1——CVE-2023-2866—3.9%
——1——CVE-2026-234745.5 MED3.9%
——1In the Linux kernel, the following vulnerability has been resolved:
mtd: Avoid boot crash in RedBoot partition table parser
Given CONFIG_FORTIFY_SOURCE=y and a recent compiler,
commit 439a1bcac648 ("fortify: Use __builtin_dynamic_object_size() when
available") produces the warning below and an oops.
Searching for RedBoot partition table in 50000000.flash at offset 0x7e0000
------------[ cut here ]------------
WARNING: lib/string_helpers.c:1035 at 0xc029e04c, CPU#0: swapper/0/1
memcmp: detected buffer overflow: 15 byte read of buffer size 14
Modules linked in:
CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0 #1 NONE
As Kees said, "'names' is pointing to the final 'namelen' many bytes
of the allocation ... 'namelen' could be basically any length at all.
This fortify warning looks legit to me -- this code used to be reading
beyond the end of the allocation."
Since the size of the dynamic allocation is calculated with strlen()
we can use strcmp() instead of memcmp() and remain within bounds.3dCVE-2024-49795—3.9%
——1——CVE-2026-121937.8 HIG3.9%
——1A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handler in the library RevoDetector.sys of the component IOCTL Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version 2.7.0 is sufficient to fix this issue. It is recommended to upgrade the affected component.3dCVE-2018-12010—3.9%
——1——CVE-2024-13961—3.9%
——1——CVE-2025-24308—3.9%
——1——CVE-2026-4309—3.9%
——1——CVE-2026-35586—3.9%
——1——