Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-36137—33.5%
——10——CVE-2006-0531—33.5%
——10——CVE-2017-16527—33.5%
——10——CVE-2022-34368—33.5%
——10——CVE-2020-9450—33.5%
——10——CVE-2026-29116—33.5%
——10A vulnerability has been found in some Dahua products could
allow an unauthenticated remote attacker to send a specially crafted packet,
triggering an exception that causes the system to reboot unexpectedly,
resulting in a denial of service.62dCVE-2023-33988—33.5%
——10——CVE-2026-53366.8 MED33.5%
——10The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the session cookies of higher privileged users who view the affected content.27dCVE-2026-240317.7 HIG33.5%
——10Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.70dCVE-1999-1330—33.5%
——10——CVE-2024-51619—33.5%
——10——CVE-2005-0602—33.5%
——10——CVE-2022-20177—33.5%
——10——CVE-2026-206366.5 MED33.5%
——10The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.70dCVE-2025-9595—33.5%
——10——CVE-2026-86784—33.5%
——10The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any higher-privileged user, such as an administrator, who reviews the affected chart.6dCVE-2016-7423—33.5%
——10——CVE-2023-24026—33.5%
——10——CVE-2026-76558—33.5%
——10The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database before inserting them into the DOM of one of its administration screens, allowing users with a role as low as contributor to perform Stored XSS attacks which will trigger in the browser of a high privileged user, such as an administrator, viewing that screen.6dCVE-2026-530069.8 CRI33.5%
——10In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix possible UAF in icmpv6_rcv()
Caching saddr and daddr before pskb_pull() is problematic
since skb->head can change.
Remove these temporary variables:
- We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr
when net_dbg_ratelimited() is called in the slow path.
- Avoid potential future misuse after pskb_pull() call.6dCVE-2021-46792—33.5%
——10——CVE-2026-65841—33.5%
——10Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6.13dCVE-2024-51602—33.5%
——10——CVE-2026-40850—33.5%
——10——CVE-2025-9773—33.5%
——10——CVE-2021-38160—33.5%
——10——CVE-2024-45809—33.5%
——10——CVE-2022-20184—33.5%
——10——CVE-2022-31454—33.5%
——10——CVE-2025-54349—33.5%
——10——CVE-2023-30267—33.5%
——10——CVE-2026-208427.0 HIG33.5%
——10Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.54dCVE-2025-10606—33.5%
——10——CVE-2025-10063—33.5%
——10——CVE-2026-21580—33.5%
——10This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server.
This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked.
Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21
Confluence Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.13
See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center and Server from the download center ([https://www.atlassian.com/software/confluence/download-archives]).
This vulnerability was reported via our Bug Bounty program.32dCVE-2017-3504—33.5%
——10——CVE-2025-10066—33.5%
——10——CVE-2024-34710—33.5%
——10——CVE-2024-7726—33.5%
——10——CVE-2025-10605—33.5%
——10——