Vulnerabilities exploitable today
352,791in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,306
- High8,002
- Medium7,177
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-25298—3.6%
——1——CVE-2026-46206—3.7%
——1——CVE-2025-46465—3.7%
——1——CVE-2025-46466—3.7%
——1——CVE-2026-529688.8 HIG3.7%
——1In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
kvm_s390_pci_aif_enable(), kvm_s390_pci_aif_disable(), and
aen_host_forward() index the GAIT by manually multiplying the index
with sizeof(struct zpci_gaite).
Since aift->gait is already a struct zpci_gaite pointer, this
double-scales the offset, accessing element aisb*16 instead of aisb.
This causes out-of-bounds accesses when aisb >= 32 (with
ZPCI_NR_DEVICES=512)
Fix by removing the erroneous sizeof multiplication.9dCVE-2026-35372—3.7%
——1——CVE-2025-69362—3.7%
——1——CVE-2026-655336.5 MED3.7%
——1Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.4dCVE-2025-66531—3.7%
——1——CVE-2023-53384—3.7%
——1——CVE-2025-432895.5 MED3.7%
——1A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to access sensitive user data.4dCVE-2025-46492—3.7%
——1——CVE-2025-25201—3.7%
——1——CVE-2020-0341—3.7%
——1——CVE-2025-20093—3.7%
——1——CVE-2024-45161—3.7%
——1——CVE-2025-46457—3.7%
——1——CVE-2022-40517—3.7%
——1——CVE-2026-6370—3.7%
——1——CVE-2025-30655—3.7%
——1——CVE-2025-46507—3.7%
——1——CVE-2024-47892—3.7%
——1——CVE-2026-46129—3.7%
——1——CVE-2026-43214—3.7%
——1——CVE-2026-46036—3.7%
——1——CVE-2022-48305—3.7%
——1——CVE-2025-46435—3.7%
——1——CVE-2025-46497—3.7%
——1——CVE-2022-32614—3.7%
——1——CVE-2025-13835—3.7%
——1——CVE-2019-2174—3.7%
——1——CVE-2026-21346—3.7%
——1——CVE-2026-43196—3.7%
——1——CVE-2026-424473.6 LOW3.7%
——1jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary tab because SummaryNode.java appends arches and perArchCount values derived from .so file path components inside an APK into an HTML panel without escaping. A malicious APK with an HTML URL-encoded ZIP entry name can force rendering of arbitrary HTML, perform out-of-band requests, disclose the victim IP address, or interact with locally exposed applications. This issue is fixed in version 1.5.6.11dCVE-2026-46209—3.7%
——1——CVE-2026-21349—3.7%
——1——CVE-2026-43128—3.7%
——1——CVE-2025-46452—3.7%
——1——CVE-2026-655286.5 MED3.7%
——1Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.4dCVE-2025-46442—3.7%
——1——