Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,415
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-12781—25.8%
——8——CVE-2024-34444—25.8%
——8——CVE-2009-0503—25.8%
——8——CVE-2026-192295.3 MED25.8%
——8A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.34dCVE-2026-53944—25.8%
——8——CVE-2023-51677—25.8%
——8——CVE-2025-67906—25.8%
——8——CVE-2026-24624—25.8%
——8——CVE-2023-51674—25.8%
——8——CVE-2026-33121—25.8%
——8——CVE-2021-47857—25.8%
——8——CVE-2023-52189—25.8%
——8——CVE-2024-11579—25.8%
——8——CVE-2025-69401—25.8%
——8——CVE-2026-29794—25.8%
——8——CVE-2023-51666—25.8%
——8——CVE-2010-2157—25.8%
——8——CVE-2023-7074—25.8%
——8——CVE-2023-44477—25.8%
——8——CVE-2020-27788—25.8%
——8——CVE-2026-658958.5 HIG25.8%
——8Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.18dCVE-2023-51403—25.8%
——8——CVE-2026-33083—25.8%
——8——CVE-2025-28438.8 HIG25.8%
——8A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create a MonitorStack in the authorized namespace and then elevate permission to the cluster level by impersonating the ServiceAccount created by the Operator, resulting in privilege escalation and other issues.45dCVE-2023-44145—25.8%
——8——CVE-2026-40399—25.8%
——8——CVE-2020-9101—25.8%
——8——CVE-2023-52125—25.8%
——8——CVE-2024-11581—25.8%
——8——CVE-2023-6390—25.8%
——8——CVE-2026-28376—25.8%
——8——CVE-2023-51520—25.8%
——8——CVE-2022-494168.8 HIG25.8%
——8In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free in chanctx code
In ieee80211_vif_use_reserved_context(), when we have an
old context and the new context's replace_state is set to
IEEE80211_CHANCTX_REPLACE_NONE, we free the old context
in ieee80211_vif_use_reserved_reassign(). Therefore, we
cannot check the old_ctx anymore, so we should set it to
NULL after this point.
However, since the new_ctx replace state is clearly not
IEEE80211_CHANCTX_REPLACES_OTHER, we're not going to do
anything else in this function and can just return to
avoid accessing the freed old_ctx.42dCVE-2025-55156—25.8%
——8——CVE-2023-4837—25.8%
——8——CVE-2023-44264—25.8%
——8——CVE-2023-52118—25.8%
——8——CVE-2026-2449—25.8%
——8——CVE-2020-0219—25.8%
——8——CVE-2012-5477—25.8%
——8——