Vulnerabilities exploitable today
351,837in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,651
New KEV · 24H0
Exploit Today ≥ 701,587
Distribution · last window
- Critical1,811
- High5,855
- Medium4,717
- Low452
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-572487.8 HIG1.9%
——1When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash during subsequent release.13dCVE-2025-20989—1.9%
——1——CVE-2024-45444—1.9%
——1——CVE-2025-26476—1.9%
——1——CVE-2022-40532—1.9%
——1——CVE-2024-42182—1.9%
——1——CVE-2022-33269—1.9%
——1——CVE-2025-24324—1.9%
——1——CVE-2024-34723—1.9%
——1——CVE-2026-44682—1.9%
——1——CVE-2026-40191—1.9%
——1——CVE-2025-48509—1.9%
——1——CVE-2024-45549—1.9%
——1——CVE-2023-22386—1.9%
——1——CVE-2023-21656—1.9%
——1——CVE-2026-50033—1.9%
——1——CVE-2026-572507.8 HIG1.9%
——1When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the application crashing.13dCVE-2026-8936—1.9%
——1——CVE-2026-131297.8 HIG1.9%
——1When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.13dCVE-2026-572547.8 HIG1.9%
——1There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the application to crash.13dCVE-2025-20629—1.9%
——1——CVE-2026-27255.3 MED1.9%
——1Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.22dCVE-2019-9268—1.9%
——1——CVE-2021-0381—1.9%
——1——CVE-2026-7882—1.9%
——1——CVE-2026-22701—1.8%
——1——CVE-2025-62309—1.9%
——1——CVE-2021-0659—1.9%
——1——CVE-2021-0421—1.9%
——1——CVE-2026-55745—1.9%
——1——CVE-2026-577577.1 HIG1.9%
——1Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.20dCVE-2022-20015—1.9%
——1——CVE-2026-572527.8 HIG1.9%
——1When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to continue accessing invalid pointers, eventually leading to the application crashing.13dCVE-2025-36144—1.9%
——1——CVE-2022-33276—1.9%
——1——CVE-2025-20696—1.9%
——1——CVE-2021-0612—1.9%
——1——CVE-2021-0665—1.9%
——1——CVE-2026-1288—1.9%
——1——CVE-2021-0666—1.9%
——1——