Vulnerabilities exploitable today
352,785in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,880
- Medium7,174
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-42931—3.5%
——1——CVE-2021-41209—3.5%
——1——CVE-2020-0285—3.5%
——1——CVE-2025-38243—3.5%
——1——CVE-2026-0124—3.5%
——1——CVE-2025-38264—3.5%
——1——CVE-2026-45027—3.5%
——1——CVE-2025-38064—3.5%
——1——CVE-2023-53417—3.5%
——1——CVE-2026-446988.3 HIG3.5%
——1Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and webkit.messageHandlers.getExternalAuth (alongside revokeExternalAuth and externalBus) on iOS. Two flaws expose the bridge to all frames (including cross-origin iframes) and unsanitized interpolation of the JavaScript callback identifier allows a cross-origin iframe rendered inside the Companion app to execute arbitrary JavaScript in the Home Assistant frontend's main-frame origin and exfiltrate the signed-in user's access token. This vulnerability is fixed in 2026.4.1 for iOS and 2026.4.4 for Android.5dCVE-2025-24772—3.5%
——1——CVE-2025-47473—3.5%
——1——CVE-2025-462805.5 MED3.5%
——1An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected system termination.3dCVE-2025-31600—3.5%
——1——CVE-2025-31602—3.5%
——1——CVE-2023-53601—3.5%
——1——CVE-2025-39938—3.5%
——1——CVE-2023-53603—3.5%
——1——CVE-2023-53393—3.5%
——1——CVE-2026-12003—3.5%
——1——CVE-2026-44995—3.5%
——1——CVE-2024-56743—3.5%
——1——CVE-2023-53412—3.5%
——1——CVE-2023-53022—3.5%
——1——CVE-2023-53597—3.5%
——1——CVE-2025-38709—3.5%
——1——CVE-2024-2207—3.5%
——1——CVE-2024-14025—3.5%
——1——CVE-2024-54102—3.5%
——1——CVE-2025-22637—3.5%
——1——CVE-2025-49446—3.5%
——1——CVE-2026-482727.8 HIG3.5%
——1Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.10dCVE-2025-49435—3.5%
——1——CVE-2025-21672—3.5%
——1——CVE-2023-47216—3.5%
——1——CVE-2024-21981—3.5%
——1——CVE-2021-41207—3.5%
——1——CVE-2020-11230—3.5%
——1——CVE-2023-38418—3.5%
——1——CVE-2025-31410—3.5%
——1——