Vulnerabilities exploitable today
352,832in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,306
- High8,005
- Medium7,178
- Low677
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-0337—3.8%
——1——CVE-2026-140635.7 MED3.8%
——1Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Low)26dCVE-2025-67460—3.8%
——1——CVE-2022-49943—3.8%
——1——CVE-2026-23755—3.8%
——1——CVE-2026-23410—3.8%
——1——CVE-2024-23589—3.8%
——1——CVE-2025-36463—3.8%
——1——CVE-2020-0295—3.8%
——1——CVE-2025-36460—3.8%
——1——CVE-2026-8484—3.8%
——1——CVE-2026-24381—3.8%
——1——CVE-2025-9883—3.8%
——1——CVE-2026-4816—3.8%
——1——CVE-2025-9078—3.8%
——1——CVE-2025-10089—3.8%
——1——CVE-2026-26074—3.8%
——1——CVE-2025-11537—3.8%
——1——CVE-2025-9882—3.8%
——1——CVE-2026-44455—3.8%
——1——CVE-2026-242324.3 MED3.8%
——1NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.6dCVE-2026-30292—3.8%
——1——CVE-2023-53522—3.8%
——1——CVE-2025-5731—3.8%
——1——CVE-2026-95975.4 MED3.8%
——1Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-0068114dCVE-2024-40594—3.8%
——1——CVE-2023-39298—3.8%
——1——CVE-2025-20198—3.8%
——1——CVE-2020-0331—3.8%
——1——CVE-2026-8997—3.8%
——1vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime check on the length of history entries in release builds, potentially allowing a crafted long path or command in the history to cause memory corruption or application crashes.
Releases from 0.12.1 to 0.14.3 (including) are considered vulnerable. This issue was fixed in commit 23063c74dCVE-2025-59480—3.8%
——1——CVE-2026-83815.4 MED3.8%
——1A broken access
control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not
correctly enforce authorization checks, allowing an authenticated user with low
privileges to perform actions and access resources intended only for higher‑privileged roles. An attacker with
low‑privileged credentials may exploit
this to gain unauthorized access to administrative or sensitive functionality.4dCVE-2025-20103—3.8%
——1——CVE-2025-39854—3.8%
——1——CVE-2025-9881—3.8%
——1——CVE-2025-62688—3.8%
——1——CVE-2025-39793—3.8%
——1——CVE-2026-433297.8 HIG3.8%
——1In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: strictly check for maximum number of actions
The maximum number of flowtable hardware offload actions in IPv6 is:
* ethernet mangling (4 payload actions, 2 for each ethernet address)
* SNAT (4 payload actions)
* DNAT (4 payload actions)
* Double VLAN (4 vlan actions, 2 for popping vlan, and 2 for pushing)
for QinQ.
* Redirect (1 action)
Which makes 17, while the maximum is 16. But act_ct supports for tunnels
actions too. Note that payload action operates at 32-bit word level, so
mangling an IPv6 address takes 4 payload actions.
Update flow_action_entry_next() calls to check for the maximum number of
supported actions.
While at it, rise the maximum number of actions per flow from 16 to 24
so this works fine with IPv6 setups.5dCVE-2020-0312—3.8%
——1——CVE-2026-537425.4 MED3.8%
——1Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.4d