Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-9369—0.3%
——0——CVE-2023-40652—0.3%
——0——CVE-2025-20774—0.3%
——0——CVE-2024-29780—0.3%
——0——CVE-2025-20775—0.3%
——0——CVE-2026-148377.8 HIG0.3%
——0Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.49dCVE-2026-586787.8 HIG0.3%
——0In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.20hCVE-2025-36105—0.3%
——0——CVE-2024-47032—0.3%
——0——CVE-2025-13492—0.3%
——0——CVE-2026-567977.3 HIG0.3%
——0Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.27dCVE-2025-20770—0.3%
——0——CVE-2026-24921—0.3%
——0——CVE-2025-48601—0.3%
——0——CVE-2025-48607—0.3%
——0——CVE-2025-20747—0.3%
——0——CVE-2025-6182—0.3%
——0——CVE-2024-40670—0.3%
——0——CVE-2022-48444—0.3%
——0——CVE-2026-180184.0 MED0.3%
——0Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)44dCVE-2023-21366—0.3%
——0——CVE-2026-586798.4 HIG0.3%
——0In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.20hCVE-2024-32927—0.3%
——0——CVE-2025-20772—0.3%
——0——CVE-2025-26462—0.3%
——0——CVE-2023-21082—0.3%
——0——CVE-2022-20013—0.3%
——0——CVE-2025-20749—0.3%
——0——CVE-2018-9412—0.3%
——0——CVE-2026-552857.8 HIG0.3%
——0In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.9dCVE-2025-48599—0.3%
——0——CVE-2026-6066—0.3%
——0——CVE-2026-204925.5 MED0.3%
——0In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.29dCVE-2025-47396—0.3%
——0——CVE-2025-46774—0.3%
——0——CVE-2026-114812.5 LOW0.3%
——0A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.57dCVE-2022-20155—0.3%
——0——CVE-2025-20776—0.3%
——0——CVE-2025-20746—0.3%
——0——CVE-2022-48443—0.3%
——0——