Vulnerabilities exploitable today
352,785in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,880
- Medium7,174
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-36893—0.1%
——0——CVE-2025-20777—0.1%
——0——CVE-2022-26450—0.1%
——0——CVE-2026-0123—0.1%
——0——CVE-2026-00967.8 HIG0.1%
——0In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.4dCVE-2024-53010—0.1%
——0——CVE-2025-48607—0.1%
——0——CVE-2024-53839—0.1%
——0——CVE-2025-20730—0.1%
——0——CVE-2025-47334—0.1%
——0——CVE-2023-21260—0.1%
——0——CVE-2025-20745—0.1%
——0——CVE-2026-00435.5 MED0.1%
——0In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.5dCVE-2026-419855.1 MED0.1%
——0UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.4dCVE-2026-252768.8 HIG0.1%
——0Memory corruption while using Strongbox due to missing bounds check.4dCVE-2022-20219—0.1%
——0——CVE-2026-261037.1 HIG0.1%
——0A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.12dCVE-2024-49736—0.1%
——0——CVE-2025-26445—0.1%
——0——CVE-2024-49735—0.1%
——0——CVE-2026-43053—0.1%
——0——CVE-2026-23153—0.1%
——0——CVE-2017-13310—0.1%
——0——CVE-2026-35374—0.1%
——0——CVE-2025-47408—0.1%
——0——CVE-2025-13492—0.1%
——0——CVE-2025-32320—0.1%
——0——CVE-2026-56272—0.1%
——0——CVE-2025-22420—0.1%
——0——CVE-2023-35645—0.1%
——0——CVE-2026-0138—0.1%
——0——CVE-2025-20776—0.1%
——0——CVE-2025-20775—0.1%
——0——CVE-2026-00486.8 MED0.1%
——0In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.5dCVE-2022-20256—0.1%
——0——CVE-2025-48599—0.1%
——0——CVE-2025-48629—0.1%
——0——CVE-2025-20778—0.1%
——0——CVE-2026-20429—0.1%
——0——CVE-2025-47406—0.1%
——0——