Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,324
- High9,979
- Medium4,918
- Low460
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-34732—0.1%
——0——CVE-2025-47369—0.1%
——0——CVE-2024-47033—0.1%
——0——CVE-2025-47377—0.1%
——0——CVE-2025-47376—0.1%
——0——CVE-2018-9344—0.1%
——0——CVE-2026-40226—0.1%
——0——CVE-2023-35645—0.1%
——0——CVE-2021-0697—0.1%
——0——CVE-2026-20429—0.1%
——0——CVE-2025-27049—0.1%
——0——CVE-2023-21290—0.1%
——0——CVE-2025-47348—0.1%
——0——CVE-2024-38418—0.1%
——0——CVE-2026-35374—0.1%
——0——CVE-2023-20939—0.1%
——0——CVE-2026-0137—0.1%
——0——CVE-2026-240766.7 MED0.1%
——0Memory Corruption when processing registry values with incorrect types using a direct query method.21dCVE-2026-21444—0.1%
——0——CVE-2025-47373—0.0%
——0——CVE-2026-240807.8 HIG0.0%
——0Memory Corruption when handling malformed request parameters in the fingerprint TA.21dCVE-2026-0150—0.0%
——0——CVE-2023-20750—0.0%
——0——CVE-2026-27875—0.0%
——0Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data.
This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.6dCVE-2026-9266—0.0%
——0——CVE-2026-00997.8 HIG0.0%
——0In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.36dCVE-2022-48451—0.0%
——0——CVE-2025-264187.8 HIG0.0%
——0In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2024-49724—0.0%
——0——CVE-2025-58313—0.0%
——0——CVE-2023-20787—0.0%
——0——CVE-2025-47378—0.0%
——0——CVE-2024-43766—0.0%
——0——CVE-2025-59603—0.0%
——0——CVE-2026-28548—0.0%
——0——CVE-2026-0145—0.0%
——0——CVE-2022-20243—0.0%
——0——CVE-2026-28538—0.0%
——0——CVE-2025-47379—0.0%
——0——CVE-2026-00695.5 MED0.0%
——0In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.36d