Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,325
- High9,981
- Medium4,918
- Low460
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-264187.8 HIG0.0%
——0In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2026-0142—0.0%
——0——CVE-2026-0145—0.0%
——0——CVE-2026-00705.5 MED0.0%
——0In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2023-20736—0.0%
——0——CVE-2026-00675.5 MED0.0%
——0In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2025-48569—0.0%
——0——CVE-2024-29779—0.0%
——0——CVE-2025-48575—0.0%
——0——CVE-2019-20775—0.0%
——0——CVE-2023-20686—0.0%
——0——CVE-2022-20243—0.0%
——0——CVE-2026-00695.5 MED0.0%
——0In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2026-20442—0.0%
——0——CVE-2025-54651—0.0%
——0——CVE-2026-28538—0.0%
——0——CVE-2025-47379—0.0%
——0——CVE-2026-28543—0.0%
——0——CVE-2026-210796.5 MED0.0%
——0Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.8dCVE-2025-58316—0.0%
——0——CVE-2026-169277.3 HIG0.0%
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition.3dCVE-2025-47333—0.0%
——0——CVE-2025-48641—0.0%
——0——CVE-2026-24930—0.0%
——0——CVE-2024-34725—0.0%
——0——CVE-2026-207572.5 LOW0.0%
——0Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server.
This issue affects Command Centre Server:
9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.9dCVE-2026-169357.8 HIG0.0%
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use (TOCTOU) race condition.3dCVE-2026-146814.2 MED0.0%
——0Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.9dCVE-2026-285777.8 HIG0.0%
——0In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2026-240807.8 HIG0.0%
——0Memory Corruption when handling malformed request parameters in the fingerprint TA.21dCVE-2023-20750—0.0%
——0——CVE-2025-47373—0.0%
——0——CVE-2026-00997.8 HIG0.0%
——0In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.36dCVE-2026-27875—0.0%
——0Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data.
This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.6dCVE-2026-9266—0.0%
——0——CVE-2022-48451—0.0%
——0——CVE-2026-0150—0.0%
——0——CVE-2025-23364—0.0%
——0——CVE-2024-53016—0.0%
——0——CVE-2026-00605.5 MED0.0%
——0In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.36d