Vulnerabilities exploitable today
376,316in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,788
- Medium6,800
- Low736
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-38539——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused21dCVE-2026-87730——
——0Rejected reason: this is rejected2dCVE-2026-51230——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.48dCVE-2025-66333—0.0%
——0——CVE-2026-24438——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.38dCVE-2026-51257——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.48dCVE-2021-47998——
——0Rejected reason: This CVE ID has been rejected.21dCVE-2023-49720——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused21dCVE-2026-26349——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.38dCVE-2025-24837——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused36dCVE-2026-56872——
——0Rejected reason: reserved but not needed30dCVE-2021-47990——
——0Rejected reason: This CVE ID has been rejected.37dCVE-2025-15065—0.0%
——0——CVE-2026-28539—0.0%
——0——CVE-2026-68941——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67312. Reason: This candidate is a duplicate of CVE-2026-67312. Notes: All CVE users should reference CVE-2026-67312 instead of this candidate.42dCVE-2023-24462——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused21dCVE-2023-28822——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused21dCVE-2026-816838.4 HIG0.0%
——0openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker with file system access can read the exposed private key. Version 1.4.9 writes the PEM to a dedicated 0600 file, keeps only its path in SharedPreferences, and migrates/scrubs existing cleartext values.15dCVE-2022-51004——
——0Rejected reason: This CVE ID has been rejected.21dCVE-2025-62310—0.0%
——0——CVE-2026-00947.8 HIG0.0%
——0In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.57dCVE-2026-19562——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.29dCVE-2026-10772——
——0Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigned to a vulnerability already covered by CVE-2026-2411, which was assigned earlier for the same defect: the Bluetooth GATT notify/indicate paths check the permissions of the Characteristic Declaration attribute rather than the Characteristic Value attribute, so the encryption/authentication requirements configured on the value are not enforced. Both identifiers describe the same root cause in subsys/bluetooth/host/gatt.c, fixed by the same commit (c3386f92fe81bd10dc23e6a115e6a80a7d863546). Use CVE-2026-2411 instead.47dCVE-2023-54376——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.43dCVE-2026-51282——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.48dCVE-2022-51003——
——0Rejected reason: This CVE ID has been rejected.21dCVE-2025-66331—0.0%
——0——CVE-2026-0112—0.0%
——0——CVE-2026-57844——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.7dCVE-2026-20438—0.0%
——0——CVE-2023-24541——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused21dCVE-2026-56716——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.18dCVE-2023-46684——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused21dCVE-2026-826405.5 MED0.0%
——0browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.7dCVE-2026-16339——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.50dCVE-2026-6258——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.26dCVE-2023-32631——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused21dCVE-2026-19563——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.29dCVE-2026-13081——
——0Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities.24dCVE-2023-21095—0.0%
——0——