Vulnerabilities exploitable today
377,415in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H3
Exploit Today ≥ 701,647
Distribution · last window
- Critical2,355
- High8,510
- Medium6,633
- Low715
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-486485.5 MED0.0%
——0In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.59dCVE-2026-286447.8 HIG0.0%
——0In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2026-9266—0.0%
——0——CVE-2026-622046.6 MED0.0%
——0SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.23dCVE-2026-28548—0.0%
——0——CVE-2025-463713.6 LOW0.0%
——0Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.57dCVE-2026-210796.5 MED0.0%
——0Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.30dCVE-2023-20834—0.0%
——0——CVE-2025-54625—0.0%
——0——CVE-2026-451972.5 LOW0.0%
——0Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory.
The firmware uses data provided by the Guest VM to set up accesses to memory. It validated this before use, but a TOCTOU bug was present which allowed the earlier check results to be invalidated.10dCVE-2026-286367.8 HIG0.0%
——0In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2026-285845.5 MED0.0%
——0In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2026-34857—0.0%
——0——CVE-2026-440594.5 MED0.0%
——0A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain limited information, modify limited data, or cause a minor service disruption.57dCVE-2025-264187.8 HIG0.0%
——0In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.59dCVE-2023-20942—0.0%
——0——CVE-2026-112905.0 MED0.0%
——0Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low)58dCVE-2026-285965.5 MED0.0%
——0In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2026-00917.8 HIG0.0%
——0In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.58dCVE-2023-44128—0.0%
——0——CVE-2022-47331—0.0%
——0——CVE-2022-20243—0.0%
——0——CVE-2025-66321—0.0%
——0——CVE-2025-27076—0.0%
——0——CVE-2026-286207.8 HIG0.0%
——0In multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2025-21473—0.0%
——0——CVE-2023-20623—0.0%
——0——CVE-2023-20788—0.0%
——0——CVE-2023-20801—0.0%
——0——CVE-2026-24930—0.0%
——0——CVE-2026-252587.8 HIG0.0%
——0Memory corruption while processing IOCTL calls for escape operations.58dCVE-2025-66327—0.0%
——0——CVE-2026-28538—0.0%
——0——CVE-2026-285727.8 HIG0.0%
——0In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2021-47993——
——0Rejected reason: This CVE ID has been rejected.38dCVE-2026-51230——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.49dCVE-2026-51262——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.49dCVE-2023-54368——
——0Rejected reason: This CVE ID has been rejected.38dCVE-2023-35768——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused22dCVE-2023-42434——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused22d