Vulnerabilities exploitable today
351,720in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,651
New KEV · 24H0
Exploit Today ≥ 701,587
Distribution · last window
- Critical1,750
- High5,599
- Medium4,484
- Low405
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-20709—1.6%
——0——CVE-2025-38711—1.6%
——0——CVE-2026-139553.3 LOW1.6%
——0Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Medium)19dCVE-2026-45905—1.6%
——0——CVE-2023-0006—1.6%
——0——CVE-2022-33275—1.6%
——0——CVE-2023-32868—1.6%
——0——CVE-2026-45613—1.6%
——0——CVE-2023-23435—1.6%
——0——CVE-2021-23243—1.6%
——0——CVE-2021-0997—1.6%
——0——CVE-2021-39688—1.6%
——0——CVE-2023-32864—1.6%
——0——CVE-2024-53023—1.5%
——0——CVE-2024-33028—1.5%
——0——CVE-2023-28549—1.5%
——0——CVE-2024-39342—1.5%
——0——CVE-2024-583502.9 LOW1.5%
——0Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers can trigger an infinite loop or denial of service during shutdown by exploiting the unsafe destruction order that causes iteration over deallocated memory.7dCVE-2024-20027—1.5%
——0——CVE-2024-43061—1.5%
——0——CVE-2023-28567—1.5%
——0——CVE-2023-33034—1.5%
——0——CVE-2021-0672—1.5%
——0——CVE-2023-33031—1.5%
——0——CVE-2024-51513—1.5%
——0——CVE-2022-20137—1.5%
——0——CVE-2025-27552—1.5%
——0——CVE-2025-38738—1.5%
——0——CVE-2025-27551—1.5%
——0——CVE-2026-57306—1.5%
——0——CVE-2025-48567—1.5%
——0——CVE-2026-22694—1.5%
——0——CVE-2025-33177—1.5%
——0——CVE-2024-23383—1.5%
——0——CVE-2024-23382—1.5%
——0——CVE-2025-36158—1.5%
——0——CVE-2025-36159—1.5%
——0——CVE-2023-28573—1.5%
——0——CVE-2026-20666—1.5%
——0——CVE-2023-33117—1.5%
——0——