Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,337
- High8,543
- Medium6,730
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-197259.1 CRI31.2%
——9The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the web root.
The file name always carries a fixed suffix and the contents are always the WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131's own log header, so only the location of the file is attacker controlled.24dCVE-2024-6548—31.2%
——9——CVE-2026-791389.6 CRI31.1%
——9Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)24dCVE-2026-30226—31.2%
——9——CVE-2025-30275—31.2%
——9——CVE-2019-2409—31.2%
——9——CVE-2026-68248.4 HIG31.2%
——9A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently stored on the device backend. When administrators or users access affected pages, the stored scripts are executed in their browsers, leading to potential session hijacking, unauthorized actions, or data theft.60dCVE-2024-36993—31.2%
——9——CVE-2026-34280—31.2%
——9——CVE-2026-790698.8 HIG31.2%
——9Memory corruption in Tint in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)24dCVE-2025-68039—31.2%
——9——CVE-2025-25729—31.2%
——9——CVE-2025-59483—31.2%
——9——CVE-2024-41443—31.2%
——9——CVE-2024-10883—31.2%
——9——CVE-2020-16610—31.2%
——9——CVE-2024-6545—31.2%
——9——CVE-2026-534666.5 MED31.2%
——9ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.79dCVE-2016-8822—31.2%
——9——CVE-2023-6181—31.2%
——9——CVE-2024-4855—31.2%
——9——CVE-2025-68003—31.2%
——9——CVE-2026-177574.3 MED31.2%
——9Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)50dCVE-2018-1409—31.2%
——9——CVE-2026-878227.5 HIG31.2%
——9t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in MergingDigest.fromBytes, allowing attackers to inject NaN values that bypass validation checks. Attackers can craft malicious serialized digests containing NaN centroids that degrade sorting performance from O(n log n) to O(n squared), causing severe processing delays during merge operations.10dCVE-2024-6571—31.2%
——9——CVE-2026-2250—31.2%
——9——CVE-2026-470267.4 HIG31.2%
——9Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N).50dCVE-2026-281677.5 HIG31.2%
——9Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.26dCVE-2026-25494—31.2%
——9——CVE-2024-41439—31.2%
——9——CVE-2026-659705.3 MED31.2%
——9OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make TIFFInput::read_native_scanlines() return through an error path while asynchronous strip-decompression work remains queued. Because task_set is declared before ok and compressed_scratch, those captured objects are destroyed before the task-set destructor waits, allowing worker tasks to use stale stack and heap storage, resulting in a use-after-scope crash and denial of service. The affected implementation is identified by src/tiff.imageio/tiffinput.cpp, TIFFInput::read_native_scanlines(), task_set, ok, compressed_scratch, and uncompress_one_strip(), which define the relevant source path, functions, state, and trigger. This issue is fixed in 3.1.16.0.1dCVE-2025-30267—31.2%
——9——CVE-2005-0179—31.2%
——9——CVE-2024-6553—31.2%
——9——CVE-2025-29901—31.2%
——9——CVE-2025-59939—31.2%
——9——CVE-2024-2696—31.2%
——9——CVE-2026-34266—31.2%
——9——CVE-2024-27993—31.2%
——9——