Vulnerabilities exploitable today
351,837in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,651
New KEV · 24H0
Exploit Today ≥ 701,587
Distribution · last window
- Critical1,811
- High5,855
- Medium4,717
- Low452
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-40191—1.9%
——1——CVE-2021-0900—1.9%
——1——CVE-2023-21630—1.9%
——1——CVE-2021-0611—1.9%
——1——CVE-2021-0610—1.9%
——1——CVE-2026-24918—1.9%
——1——CVE-2022-33232—1.9%
——1——CVE-2022-25723—1.9%
——1——CVE-2023-21632—1.9%
——1——CVE-2023-21337—1.9%
——1——CVE-2026-572427.8 HIG1.9%
——1The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null value validation; when the page state changes, the application continuously dereferences invalid objects, eventually leading to a crash.13dCVE-2025-32007—1.9%
——1——CVE-2026-13282—1.9%
——1——CVE-2025-20104—1.9%
——1——CVE-2022-25713—1.9%
——1——CVE-2025-13455—1.9%
——1——CVE-2026-7882—1.9%
——1——CVE-2021-0381—1.9%
——1——CVE-2025-15569—1.9%
——1——CVE-2021-0653—1.8%
——1——CVE-2026-572457.8 HIG1.9%
——1When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to validate the abnormal annotation relationships and field combinations. This results in the internal objects entering an invalid state. Eventually, during the destruction phase, an invalid pointer write occurred, causing the application to crash.13dCVE-2026-35344—1.9%
——1——CVE-2022-33300—1.9%
——1——CVE-2025-38477—1.9%
——1——CVE-2025-61971—1.9%
——1——CVE-2020-11277—1.9%
——1——CVE-2026-20628—1.9%
——1——CVE-2026-33850—1.9%
——1——CVE-2022-33307—1.9%
——1——CVE-2026-27255.3 MED1.9%
——1Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.22dCVE-2023-21656—1.9%
——1——CVE-2026-55745—1.9%
——1——CVE-2021-0659—1.9%
——1——CVE-2026-577577.1 HIG1.9%
——1Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.20dCVE-2023-24854—1.9%
——1——CVE-2022-20015—1.9%
——1——CVE-2025-58408—1.9%
——1——CVE-2021-0421—1.9%
——1——CVE-2026-31395—1.9%
——1——CVE-2026-131267.8 HIG1.9%
——1The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.13d