Vulnerabilities exploitable today
363,707in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,925
- High12,301
- Medium7,512
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-409534.4 MED0.1%
——0CVE-2026-40953 is a heap overflow in the
certificate parsing function of Secure Access clients prior to 14.55. Attackers
with local access and administrator permissions can create a denial of service
attack against the client over which they have control.36dCVE-2025-47348—0.1%
——0——CVE-2025-47369—0.1%
——0——CVE-2026-00967.8 HIG0.1%
——0In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2026-0137—0.1%
——0——CVE-2025-21455—0.1%
——0——CVE-2026-00605.5 MED0.1%
——0In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2026-0123—0.1%
——0——CVE-2026-00745.5 MED0.1%
——0In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2024-47026—0.1%
——0——CVE-2025-47406—0.1%
——0——CVE-2025-47393—0.1%
——0——CVE-2025-27049—0.1%
——0——CVE-2025-66327—0.0%
——0——CVE-2026-213837.1 HIG0.0%
——0Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.44dCVE-2025-48960—0.0%
——0——CVE-2026-25266—0.0%
——0——CVE-2026-0145—0.0%
——0——CVE-2026-0057—0.0%
——0——CVE-2025-54625—0.0%
——0——CVE-2025-47385—0.0%
——0——CVE-2026-24413—0.0%
——0——CVE-2023-20623—0.0%
——0——CVE-2026-178726.1 MED0.0%
——0Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)18dCVE-2025-48575—0.0%
——0——CVE-2023-20685—0.0%
——0——CVE-2026-00997.8 HIG0.0%
——0In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.30dCVE-2024-34725—0.0%
——0——CVE-2026-210796.5 MED0.0%
——0Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.2dCVE-2024-43766—0.0%
——0——CVE-2025-23364—0.0%
——0——CVE-2023-21101—0.0%
——0——CVE-2025-54651—0.0%
——0——CVE-2025-36889—0.0%
——0——CVE-2023-20620—0.0%
——0——CVE-2025-58313—0.0%
——0——CVE-2025-47374—0.0%
——0——CVE-2026-28548—0.0%
——0——CVE-2026-112905.0 MED0.0%
——0Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low)29dCVE-2024-47025—0.0%
——0——