Vulnerabilities exploitable today
351,920in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical1,901
- High6,163
- Medium4,997
- Low479
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-2345—0.0%
——0——CVE-2023-20685—0.0%
——0——CVE-2023-37395—0.0%
——0——CVE-2026-34862—0.0%
——0——CVE-2023-20686—0.0%
——0——CVE-2023-20687—0.0%
——0——CVE-2026-34861—0.0%
——0——CVE-2025-48641—0.0%
——0——CVE-2023-21399—0.0%
——0——CVE-2024-45547—0.0%
——0——CVE-2025-58303—0.0%
——0——CVE-2026-213837.1 HIG0.0%
——0Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.15dCVE-2025-36751—0.0%
——0——CVE-2022-38690—0.0%
——0——CVE-2026-50267—0.0%
——0——CVE-2023-20801—0.0%
——0——CVE-2022-48451—0.0%
——0——CVE-2026-00163.3 LOW0.0%
——0In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.21hCVE-2025-47385—0.0%
——0——CVE-2025-48569—0.0%
——0——CVE-2025-20789—0.0%
——0——CVE-2026-0125—0.0%
——0——CVE-2026-3229—0.0%
——0——CVE-2023-21290—0.0%
——0——CVE-2025-596156.6 MED0.0%
——0Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.16dCVE-2024-43766—0.0%
——0——CVE-2025-21473—0.0%
——0——CVE-2026-21002—0.0%
——0——CVE-2023-20834—0.0%
——0——CVE-2026-0008—0.0%
——0——CVE-2024-53016—0.0%
——0——CVE-2026-285863.3 LOW0.0%
——0In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.11hCVE-2026-0150—0.0%
——0——CVE-2026-44509—0.0%
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.2dCVE-2024-29779—0.0%
——0——CVE-2026-0142—0.0%
——0——CVE-2025-48608—0.0%
——0——CVE-2026-165172.9 LOW0.0%
——0A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.10hCVE-2026-61692——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61454. Reason: This candidate is a duplicate of CVE-2026-61454. Notes: All CVE users should reference CVE-2026-61454 instead of this candidate.10dCVE-2026-28549—0.0%
——0——