Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-6184—29.4%
——9——CVE-2026-563275.3 MED29.4%
——9Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers can call the SECURITY DEFINER function with a publishable API key to determine if an organization ID exists based on NO_ORG versus NO_RIGHTS responses, enabling tenant enumeration attacks.79dCVE-2025-8676—29.4%
——9——CVE-2022-26358—29.4%
——9——CVE-2026-198757.5 HIG29.4%
——9IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.22dCVE-2024-2788—29.4%
——9——CVE-2024-3053—29.4%
——9——CVE-2026-790208.1 HIG29.4%
——9Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted media file. (Chromium security severity: Medium)18dCVE-2025-58095—29.4%
——9——CVE-2025-47996—29.4%
——9——CVE-2025-49675—29.4%
——9——CVE-2024-49655—29.4%
——9——CVE-2020-37200—29.4%
——9——CVE-2025-48816—29.4%
——9——CVE-2024-42018—29.4%
——9——CVE-2023-46736—29.4%
——9——CVE-2025-1766—29.4%
——9——CVE-2023-23989—29.4%
——9——CVE-2025-46717—29.4%
——9——CVE-2023-25556—29.4%
——9——CVE-2025-2202—29.4%
——9——CVE-2024-43256—29.4%
——9——CVE-2021-47717—29.4%
——9——CVE-2026-25958—29.4%
——9——CVE-2023-41045—29.4%
——9——CVE-2024-6438—29.4%
——9——CVE-2024-236838.2 HIG29.4%
——9Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.65dCVE-2025-43727—29.4%
——9——CVE-2025-5783—29.4%
——9——CVE-2017-8064—29.4%
——9——CVE-2025-385147.5 HIG29.4%
——9In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix oops due to non-existence of prealloc backlog struct
If an AF_RXRPC service socket is opened and bound, but calls are
preallocated, then rxrpc_alloc_incoming_call() will oops because the
rxrpc_backlog struct doesn't get allocated until the first preallocation is
made.
Fix this by returning NULL from rxrpc_alloc_incoming_call() if there is no
backlog struct. This will cause the incoming call to be aborted.50dCVE-2018-14980—29.4%
——9——CVE-2026-156179.1 CRI29.4%
——9Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.53dCVE-2026-121448.8 HIG29.4%
——9The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check such as `current_user_can('promote_users')` or `current_user_can('manage_options')`. This makes it possible for authenticated attackers with author-level access and above to escalate their privileges to administrator by supplying `administrator` as the `user_role_set` value in a crafted request. The function is gated only by a nonce (`request_user_role_nonce`) that is rendered in the meta box on the `wwp_requests` post edit screen; because the post type is registered with `capability_type => 'post'`, any author-level user who has authored a `wwp_requests` post — such as one created via the wholesale registration form — can access this nonce and submit the role-assignment request.50dCVE-2025-63212—29.4%
——9——CVE-2024-456153.9 LOW29.4%
——9A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK.
The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).80dCVE-2005-2231—29.4%
——9——CVE-2015-0990—29.4%
——9——CVE-2024-0427—29.4%
——9——CVE-2017-17852—29.4%
——9——