Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,324
- High9,977
- Medium4,917
- Low460
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-23153—0.1%
——0——CVE-2024-49840—0.1%
——0——CVE-2025-48560—0.1%
——0——CVE-2025-58296—0.1%
——0——CVE-2026-0123—0.1%
——0——CVE-2025-47357—0.1%
——0——CVE-2026-00967.8 HIG0.1%
——0In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2025-21455—0.1%
——0——CVE-2023-6728—0.1%
——0——CVE-2017-13312—0.1%
——0——CVE-2025-31356—0.1%
——0Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without any user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and no effect on availability. Subsequent system impacts include reduced confidentiality (low), integrity (low), and no effect on availability.15dCVE-2017-13311—0.1%
——0——CVE-2026-28547—0.1%
——0——CVE-2017-13314—0.1%
——0——CVE-2022-26450—0.1%
——0——CVE-2026-168967.1 HIG0.1%
——0IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) race condition.10dCVE-2025-47375—0.1%
——0——CVE-2025-20805—0.1%
——0——CVE-2026-49365.1 MED0.1%
——0IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.2dCVE-2021-0696—0.1%
——0——CVE-2024-9858—0.1%
——0——CVE-2025-54422—0.1%
——0——CVE-2024-47028—0.1%
——0——CVE-2026-285814.0 MED0.1%
——0In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation.36dCVE-2026-24929—0.1%
——0——CVE-2025-21431—0.1%
——0——CVE-2026-419855.1 MED0.1%
——0UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.35dCVE-2025-27041—0.1%
——0——CVE-2024-47026—0.1%
——0——CVE-2024-47016—0.1%
——0——CVE-2026-0138—0.1%
——0——CVE-2026-00435.5 MED0.1%
——0In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2026-11347—0.1%
——0——CVE-2025-52532—0.1%
——0——CVE-2024-47034—0.1%
——0——CVE-2024-0028—0.1%
——0——CVE-2021-39660—0.1%
——0——CVE-2025-36921—0.1%
——0——CVE-2026-65055.1 MED0.1%
——0The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.16dCVE-2025-36751—0.1%
——0——