Vulnerabilities exploitable today
352,785in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,880
- Medium7,174
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-39857—3.5%
——1——CVE-2023-53667—3.5%
——1——CVE-2025-27332—3.5%
——1——CVE-2025-38271—3.5%
——1——CVE-2026-121917.8 HIG3.5%
——1A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack is only possible with local access. The vendor was contacted early about this disclosure but did not respond in any way.2dCVE-2019-20600—3.5%
——1——CVE-2026-416943.7 LOW3.5%
——1Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle.
Affected versions:
Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.4dCVE-2024-34641—3.5%
——1——CVE-2025-27021—3.5%
——1——CVE-2025-38633—3.5%
——1——CVE-2025-39909—3.5%
——1——CVE-2025-38266—3.5%
——1——CVE-2026-73497.5 HIG3.5%
——1Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)3dCVE-2025-0360—3.5%
——1——CVE-2024-9949—3.5%
——1——CVE-2025-10887—3.5%
——1——CVE-2026-20641—3.5%
——1——CVE-2023-40216—3.5%
——1——CVE-2025-38284—3.5%
——1——CVE-2026-111816.3 MED3.5%
——1Inappropriate implementation in Media Session in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)4dCVE-2023-53598—3.5%
——1——CVE-2023-53501—3.5%
——1——CVE-2025-39890—3.5%
——1——CVE-2025-38287—3.5%
——1——CVE-2023-53380—3.5%
——1——CVE-2023-30700—3.5%
——1——CVE-2025-40579—3.5%
——1——CVE-2026-27798—3.5%
——1——CVE-2026-26072—3.5%
——1——CVE-2024-9834—3.5%
——1——CVE-2023-30718—3.5%
——1——CVE-2025-38442—3.5%
——1——CVE-2024-36340—3.5%
——1——CVE-2023-30684—3.5%
——1——CVE-2025-39844—3.5%
——1——CVE-2025-0478—3.5%
——1——CVE-2025-39949—3.5%
——1——CVE-2025-38613—3.5%
——1——CVE-2023-53431—3.5%
——1——CVE-2026-452465.5 MED3.5%
——1Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default filesystem permissions. When the refresh-free path rewrites the configuration file, it creates the replacement with default process umask permissions instead of preserving the original file permissions, exposing the config file containing API keys and provider credentials to other local users on shared Unix-like systems.12d