Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,215
- High7,863
- Medium6,398
- Low708
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-3115—27.9%
——8——CVE-1999-0732—27.9%
——8——CVE-2005-1088—27.9%
——8——CVE-2004-2197—27.9%
——8——CVE-2013-3368—27.9%
——8——CVE-2025-4077—27.9%
——8——CVE-2011-3289—27.9%
——8——CVE-2003-1076—27.9%
——8——CVE-2026-57645—27.9%
——8——CVE-2004-2204—27.9%
——8——CVE-2023-7328—27.9%
——8——CVE-2024-13841—27.9%
——8——CVE-2020-36394—27.9%
——8——CVE-2026-07386.4 MED27.9%
——8The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all versions up to, and including, 7.4.8. This is due to insufficient input sanitization and output escaping in the 'su_slide_link' attachment meta field. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.54dCVE-2025-22544—27.9%
——8——CVE-2026-507228.1 HIG27.9%
——8Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not affected.69dCVE-2021-420596.7 MED27.9%
——8An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.35.41, and Kernel 5.4 before 05.42.20. A stack-based buffer overflow leads toarbitrary code execution in UEFI DisplayTypeDxe DXE driver.36dCVE-2021-31519—27.9%
——8——CVE-2003-1059—27.9%
——8——CVE-2025-24627—27.9%
——8——CVE-2004-2205—27.9%
——8——CVE-2007-6207—27.9%
——8——CVE-2025-14302—27.9%
——8——CVE-2024-8493—27.9%
——8——CVE-2017-15288—27.9%
——8——CVE-2025-22515—27.9%
——8——CVE-2003-1155—27.9%
——8——CVE-2024-27107—27.9%
——8——CVE-2026-595477.5 HIG27.9%
——8Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.55dCVE-2025-22532—27.9%
——8——CVE-2025-22554—27.9%
——8——CVE-2024-23514—27.9%
——8——CVE-2024-9884—27.9%
——8——CVE-2025-22511—27.9%
——8——CVE-2024-13514—27.9%
——8——CVE-2024-8542—27.9%
——8——CVE-2026-2682—27.9%
——8——CVE-2003-1074—27.9%
——8——CVE-2026-394487.5 HIG27.9%
——8Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.76dCVE-2026-32965—27.9%
——8——