Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-26461—0.2%
——0——CVE-2026-788077.1 HIG0.2%
——0An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c6dCVE-2026-493056.2 MED0.2%
——0Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability.22dCVE-2025-47380—0.2%
——0——CVE-2023-42646—0.2%
——0——CVE-2023-42651—0.2%
——0——CVE-2025-26429—0.2%
——0——CVE-2026-552947.8 HIG0.2%
——0In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.9dCVE-2024-39435—0.2%
——0——CVE-2025-27062—0.2%
——0——CVE-2025-4737—0.2%
——0——CVE-2025-47346—0.2%
——0——CVE-2024-49745—0.2%
——0——CVE-2023-42652—0.2%
——0——CVE-2026-7997—0.2%
——0——CVE-2024-44092—0.2%
——0——CVE-2024-40650—0.2%
——0——CVE-2026-22163—0.2%
——0——CVE-2024-43077—0.2%
——0——CVE-2024-53837—0.2%
——0——CVE-2024-47012—0.2%
——0——CVE-2024-20055—0.2%
——0——CVE-2026-493157.1 HIG0.2%
——0DoS vulnerability in the input device module.
Impact: Successful exploitation of this vulnerability may affect availability.8dCVE-2024-20115—0.2%
——0——CVE-2024-20120—0.2%
——0——CVE-2025-20769—0.2%
——0——CVE-2026-559978.8 HIG0.2%
——0Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster.16dCVE-2026-455317.8 HIG0.2%
——0In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.7dCVE-2024-20109—0.2%
——0——CVE-2026-419876.2 MED0.2%
——0Permission control vulnerability in the app management module.
Impact: Successful exploitation of this vulnerability may affect availability.8dCVE-2026-179937.0 HIG0.2%
——0Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)49dCVE-2025-54655—0.2%
——0——CVE-2026-213705.3 MED0.2%
——0Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.72dCVE-2025-47343—0.2%
——0——CVE-2023-42639—0.2%
——0——CVE-2024-27230—0.2%
——0——CVE-2025-32313—0.2%
——0——CVE-2023-42640—0.2%
——0——CVE-2026-329887.5 HIG0.2%
——0OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.55dCVE-2025-20764—0.2%
——0——