Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-14600—26.7%
——8——CVE-2025-14090—26.7%
——8——CVE-2025-66570—26.7%
——8——CVE-2025-30126—26.7%
——8——CVE-2025-29488—26.7%
——8——CVE-2026-95194.3 MED26.7%
——8A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/signIn.tsx of the component Sign-in Auto-Redirect. The manipulation of the argument redirect results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.55dCVE-2024-9705—26.7%
——8——CVE-2026-2211—26.7%
——8——CVE-2024-3838—26.7%
——8——CVE-2023-6456—26.7%
——8——CVE-2026-95204.3 MED26.7%
——8A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/LoginForm.tsx of the component Sign-in. This manipulation of the argument Next causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.55dCVE-2026-559842.7 LOW26.7%
——8Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service20dCVE-2026-1118—26.7%
——8——CVE-2026-645788.2 HIG26.7%
——8In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate compound request size before reading StructureSize2
When ksmbd validates a compound (chained) SMB2 request,
ksmbd_smb2_check_message() reads pdu->StructureSize2 without first
checking that the compound element is large enough to contain it.
StructureSize2 is a 2-byte field at offset 64
(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.
The compound-walking logic only guarantees that a full 64-byte SMB2
header is present for the trailing element: when NextCommand is 0, len is
reduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A
remote client can craft a compound request whose last element has exactly
64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte
past the receive buffer, producing a slab-out-of-bounds read.
BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)
Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14
The buggy address is located 172 bytes inside of allocated 173-byte region
Workqueue: ksmbd-io handle_ksmbd_work
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)
handle_ksmbd_work (fs/smb/server/server.c:119)
process_one_work (kernel/workqueue.c:3314)
worker_thread (kernel/workqueue.c:3397)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
Reject any compound element that is too small to hold StructureSize2
before dereferencing it.27dCVE-2023-44262—26.7%
——8——CVE-2019-1866—26.7%
——8——CVE-2025-29492—26.7%
——8——CVE-2024-20327—26.7%
——8——CVE-2015-6394—26.7%
——8——CVE-2013-3273—26.7%
——8——CVE-2026-349735.3 MED26.7%
——8phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the searchCustomPages() method in phpmyfaq/src/phpMyFAQ/Search.php uses real_escape_string() (via escape()) to sanitize the search term before embedding it in LIKE clauses. However, real_escape_string() does not escape SQL LIKE metacharacters % (match any sequence) and _ (match any single character). An unauthenticated attacker can inject these wildcards into search queries, causing them to match unintended records — including content that was not meant to be surfaced — resulting in information disclosure. This issue has been patched in version 4.1.1.53dCVE-2019-14826—26.7%
——8——CVE-2025-1935—26.7%
——8——CVE-2026-578574.3 MED26.7%
——8The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET parameter is passed directly to wc_add_notice() in flowpayment-fl.php (lines 57-58) without input sanitization (for example sanitize_text_field()) or output escaping (for example esc_html()) before being rendered in the checkout notice HTML. An unauthenticated attacker can craft a URL containing a JavaScript payload in the error_message parameter (for example /checkout/?add-to-cart={product-id}&cancel_order=true&error_message={payload}); when a victim with an active WooCommerce checkout session follows the link, the payload executes in the victim's browser in the origin of the WordPress site.55dCVE-2007-0728—26.7%
——8——CVE-2025-29493—26.7%
——8——CVE-2023-44230—26.7%
——8——CVE-2019-14612—26.7%
——8——CVE-2023-51685—26.7%
——8——CVE-2026-45017—26.7%
——8——CVE-2026-31969—26.7%
——8——CVE-2023-44239—26.7%
——8——CVE-2026-26290—26.7%
——8——CVE-2021-45657—26.7%
——8——CVE-2026-47216—26.7%
——8——CVE-2019-0021—26.7%
——8——CVE-2020-9069—26.7%
——8——CVE-2026-2197—26.7%
——8——CVE-2026-2195—26.7%
——8——CVE-2019-14626—26.7%
——8——