Vulnerabilities exploitable today
363,707in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,921
- High12,266
- Medium7,474
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-27041—0.1%
——0——CVE-2026-20908—0.1%
——0Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.8dCVE-2024-49742—0.1%
——0——CVE-2026-419855.1 MED0.1%
——0UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.29dCVE-2017-13310—0.1%
——0——CVE-2026-6412—0.1%
——0——CVE-2025-47386—0.1%
——0——CVE-2026-54055—0.1%
——0——CVE-2022-44420—0.1%
——0——CVE-2025-471475.7 MED0.1%
——0Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration.
This issue affects Command Centre Mobile Client versions prior to 9.40.123.7dCVE-2025-47376—0.1%
——0——CVE-2025-47377—0.1%
——0——CVE-2024-45560—0.1%
——0——CVE-2026-0143—0.1%
——0——CVE-2021-39660—0.1%
——0——CVE-2025-47375—0.1%
——0——CVE-2025-47357—0.1%
——0——CVE-2025-47381—0.1%
——0——CVE-2025-47331—0.1%
——0——CVE-2026-419815.3 MED0.1%
——0Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.29dCVE-2025-47343—0.1%
——0——CVE-2023-6728—0.1%
——0——CVE-2025-323487.8 HIG0.1%
——0In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2026-00615.9 MED0.1%
——0In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2025-47339—0.1%
——0——CVE-2025-20799—0.1%
——0——CVE-2025-47373—0.1%
——0——CVE-2026-00367.8 HIG0.1%
——0In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2026-20429—0.1%
——0——CVE-2025-52532—0.1%
——0——CVE-2025-27032—0.1%
——0——CVE-2026-56272—0.1%
——0——CVE-2026-40226—0.1%
——0——CVE-2025-36921—0.1%
——0——CVE-2023-20939—0.1%
——0——CVE-2026-419743.6 LOW0.1%
——0Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.29dCVE-2017-13312—0.1%
——0——CVE-2024-34732—0.1%
——0——CVE-2017-13314—0.1%
——0——CVE-2017-13311—0.1%
——0——