Vulnerabilities exploitable today
363,707in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,921
- High12,266
- Medium7,474
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-47337—0.1%
——0——CVE-2024-47041—0.1%
——0——CVE-2026-00435.5 MED0.1%
——0In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2026-418608.8 HIG0.1%
——0CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials.
Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later30dCVE-2025-20785—0.1%
——0——CVE-2026-285814.0 MED0.1%
——0In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation.30dCVE-2026-26104—0.1%
——0——CVE-2024-45565—0.1%
——0——CVE-2026-41051—0.1%
——0——CVE-2026-24509—0.1%
——0——CVE-2026-00795.5 MED0.1%
——0In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.32dCVE-2025-31944—0.1%
——0——CVE-2025-485707.8 HIG0.1%
——0In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2026-0137—0.1%
——0——CVE-2025-27049—0.1%
——0——CVE-2024-47028—0.1%
——0——CVE-2025-2909—0.1%
——0——CVE-2025-47348—0.1%
——0——CVE-2025-47396—0.1%
——0——CVE-2025-47393—0.1%
——0——CVE-2026-0123—0.1%
——0——CVE-2026-00745.5 MED0.1%
——0In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2025-20796—0.1%
——0——CVE-2026-00967.8 HIG0.1%
——0In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2024-47026—0.1%
——0——CVE-2026-00605.5 MED0.1%
——0In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2025-47369—0.1%
——0——CVE-2026-409534.4 MED0.1%
——0CVE-2026-40953 is a heap overflow in the
certificate parsing function of Secure Access clients prior to 14.55. Attackers
with local access and administrator permissions can create a denial of service
attack against the client over which they have control.36dCVE-2025-21455—0.1%
——0——CVE-2025-20800—0.1%
——0——CVE-2025-47380—0.1%
——0——CVE-2025-27039—0.1%
——0——CVE-2026-24929—0.1%
——0——CVE-2025-2713—0.1%
——0——CVE-2023-21290—0.1%
——0——CVE-2025-20799—0.1%
——0——CVE-2025-47339—0.1%
——0——CVE-2026-40226—0.1%
——0——CVE-2026-20429—0.1%
——0——CVE-2025-48569—0.1%
——0——