Vulnerabilities exploitable today
356,393in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603
Distribution · last window
- Critical2,794
- High11,183
- Medium7,442
- Low701
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-20442—0.0%
——0——CVE-2026-00163.3 LOW0.0%
——0In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.16dCVE-2026-0153—0.0%
——0——CVE-2026-178726.1 MED0.0%
——0Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)4dCVE-2023-20787—0.0%
——0——CVE-2025-54651—0.0%
——0——CVE-2026-0133—0.0%
——0——CVE-2025-463713.6 LOW0.0%
——0Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.14dCVE-2026-20439—0.0%
——0——CVE-2026-213797.8 HIG0.0%
——0Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.30dCVE-2025-54625—0.0%
——0——CVE-2025-57806—0.0%
——0——CVE-2026-28548—0.0%
——0——CVE-2025-36751—0.0%
——0——CVE-2022-47331—0.0%
——0——CVE-2026-28537—0.0%
——0——CVE-2026-00897.8 HIG0.0%
——0In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.15dCVE-2023-21290—0.0%
——0——CVE-2025-48625—0.0%
——0——CVE-2023-44128—0.0%
——0——CVE-2025-47385—0.0%
——0——CVE-2025-58740—0.0%
——0——CVE-2025-596166.6 MED0.0%
——0Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.30dCVE-2025-486485.5 MED0.0%
——0In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.16dCVE-2026-3229—0.0%
——0——CVE-2026-34862—0.0%
——0——CVE-2023-20750—0.0%
——0——CVE-2026-00997.8 HIG0.0%
——0In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.15dCVE-2026-24413—0.0%
——0——CVE-2025-264187.8 HIG0.0%
——0In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.16dCVE-2025-48641—0.0%
——0——CVE-2023-20620—0.0%
——0——CVE-2026-112905.0 MED0.0%
——0Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low)15dCVE-2025-48575—0.0%
——0——CVE-2026-34857—0.0%
——0——CVE-2023-20623—0.0%
——0——CVE-2026-440594.5 MED0.0%
——0A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain limited information, modify limited data, or cause a minor service disruption.14dCVE-2026-252587.8 HIG0.0%
——0Memory corruption while processing IOCTL calls for escape operations.15dCVE-2025-47333—0.0%
——0——CVE-2026-21002—0.0%
——0——