Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-45010—26.5%
——8——CVE-2023-5427—26.5%
——8——CVE-2026-22097—26.5%
——8The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.64dCVE-2026-775007.8 HIG26.5%
——8Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.7dCVE-2025-9587—26.5%
——8——CVE-2025-14926—26.5%
——8——CVE-2024-53842—26.5%
——8——CVE-2023-48682—26.5%
——8——CVE-2025-7103—26.5%
——8——CVE-2016-3484—26.5%
——8——CVE-2026-631025.4 MED26.5%
——8rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest to mass-assign the Admin role directly to the User model, granting access to privileged features. rConfig Pro and Enterprise are not affected.27dCVE-2024-5554—26.5%
——8——CVE-2026-503024.2 MED26.5%
——8Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.55dCVE-2025-61595—26.5%
——8——CVE-2026-759205.3 MED26.5%
——8phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.14dCVE-2024-4486—26.5%
——8——CVE-2026-39308—26.5%
——8——CVE-2026-180228.8 HIG26.5%
——8Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.27dCVE-2026-6201—26.5%
——8——CVE-2024-43758—26.5%
——8——CVE-2024-56363—26.5%
——8——CVE-2025-1496—26.5%
——8——CVE-2024-47425—26.5%
——8——CVE-2025-40605—26.5%
——8——CVE-2025-22682—26.5%
——8——CVE-2023-4104—26.5%
——8——CVE-2024-21284—26.5%
——8——CVE-2024-47424—26.5%
——8——CVE-2016-6249—26.5%
——8——CVE-2025-53535—26.5%
——8——CVE-2024-9118—26.5%
——8——CVE-2025-22684—26.5%
——8——CVE-2025-45009—26.5%
——8——CVE-2019-25640—26.5%
——8——CVE-2023-527698.8 HIG26.5%
——8In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix htt mlo-offset event locking
The ath12k active pdevs are protected by RCU but the htt mlo-offset
event handling code calling ath12k_mac_get_ar_by_pdev_id() was not
marked as a read-side critical section.
Mark the code in question as an RCU read-side critical section to avoid
any potential use-after-free issues.
Compile tested only.43dCVE-2025-59039—26.5%
——8——CVE-2026-6302—26.5%
——8——CVE-2024-28224—26.5%
——8——CVE-2025-24620—26.5%
——8——CVE-2026-44319.1 CRI26.5%
——8The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is supplied. This makes it possible for unauthenticated attackers to modify the title, content, excerpt, categories, and tags of arbitrary posts, as well as change the post status to draft (effectively unpublishing them) via the 'postId' parameter.34d