Vulnerabilities exploitable today
352,785in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,880
- Medium7,174
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-20805—0.1%
——0——CVE-2025-47375—0.1%
——0——CVE-2025-47376—0.1%
——0——CVE-2025-47377—0.1%
——0——CVE-2026-00615.9 MED0.1%
——0In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.4dCVE-2023-20939—0.1%
——0——CVE-2025-47373—0.1%
——0——CVE-2025-59603—0.1%
——0——CVE-2026-00745.5 MED0.1%
——0In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.4dCVE-2025-47393—0.1%
——0——CVE-2025-47379—0.1%
——0——CVE-2026-00675.5 MED0.1%
——0In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.4dCVE-2025-47321—0.1%
——0——CVE-2024-9858—0.1%
——0——CVE-2025-323487.8 HIG0.1%
——0In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.4dCVE-2025-47320—0.1%
——0——CVE-2025-4737—0.1%
——0——CVE-2025-47380—0.1%
——0——CVE-2025-27049—0.1%
——0——CVE-2025-20785—0.1%
——0——CVE-2025-47394—0.1%
——0——CVE-2023-21466—0.1%
——0——CVE-2024-47026—0.1%
——0——CVE-2025-52532—0.1%
——0——CVE-2024-0028—0.1%
——0——CVE-2025-47388—0.1%
——0——CVE-2026-00705.5 MED0.1%
——0In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.4dCVE-2026-585574.8 MED0.1%
——0Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability.11dCVE-2025-47381—0.1%
——0——CVE-2025-36936—0.1%
——0——CVE-2025-47348—0.1%
——0——CVE-2025-47339—0.1%
——0——CVE-2026-0134—0.1%
——0——CVE-2025-20764—0.1%
——0——CVE-2025-48560—0.1%
——0——CVE-2025-27041—0.1%
——0——CVE-2025-20802—0.1%
——0——CVE-2025-20765—0.1%
——0——CVE-2024-47034—0.1%
——0——CVE-2025-20787—0.1%
——0——