Vulnerabilities exploitable today
352,785in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,880
- Medium7,174
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-41964—0.1%
——0——CVE-2023-21234—0.1%
——0——CVE-2024-29778—0.1%
——0——CVE-2026-00937.8 HIG0.1%
——0In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.4dCVE-2026-467326.7 MED0.1%
——0Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.16dCVE-2026-34858—0.1%
——0——CVE-2026-419784.4 MED0.1%
——0Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.4dCVE-2026-0138—0.1%
——0——CVE-2023-35645—0.1%
——0——CVE-2026-00486.8 MED0.1%
——0In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.5dCVE-2025-27039—0.1%
——0——CVE-2025-47405—0.1%
——0——CVE-2026-6412—0.1%
——0——CVE-2026-54327—0.1%
——0——CVE-2025-48632—0.1%
——0——CVE-2025-596067.8 HIG0.1%
——0Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.4dCVE-2026-419743.6 LOW0.1%
——0Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.4dCVE-2026-00866.8 MED0.1%
——0In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.4dCVE-2026-418608.8 HIG0.1%
——0CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials.
Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later4dCVE-2024-53010—0.1%
——0——CVE-2024-53839—0.1%
——0——CVE-2025-20730—0.1%
——0——CVE-2025-20745—0.1%
——0——CVE-2025-20777—0.1%
——0——CVE-2023-21260—0.1%
——0——CVE-2025-47334—0.1%
——0——CVE-2026-0123—0.1%
——0——CVE-2025-36893—0.1%
——0——CVE-2025-32316—0.1%
——0——CVE-2026-34849—0.1%
——0——CVE-2025-47406—0.1%
——0——CVE-2025-26437—0.1%
——0——CVE-2024-47013—0.1%
——0——CVE-2026-23115—0.1%
——0——CVE-2025-20773—0.1%
——0——CVE-2024-32921—0.1%
——0——CVE-2025-48551—0.1%
——0——CVE-2025-35054—0.1%
——0——CVE-2017-13311—0.1%
——0——CVE-2017-13312—0.1%
——0——