Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-501336.1 MED25.6%
——8Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically .html files under /content, or pages produced by a content adapter that sets content.mediaType = "text/html") had their body emitted verbatim into the rendered page. A site that ingests HTML content from an untrusted source could therefore be served stored cross-site scripting. This vulnerability is fixed in 0.162.0.70dCVE-2025-25736—25.6%
——8——CVE-2023-44208—25.6%
——8——CVE-2024-12078—25.6%
——8——CVE-2021-0654—25.6%
——8——CVE-2020-11031—25.6%
——8——CVE-2010-0825—25.6%
——8——CVE-2020-0504—25.6%
——8——CVE-1999-0850—25.6%
——8——CVE-2024-43430—25.6%
——8——CVE-2026-54193—25.6%
——8——CVE-2025-50340—25.6%
——8——CVE-2023-42874—25.6%
——8——CVE-2024-13413—25.6%
——8——CVE-2025-4011—25.6%
——8——CVE-2024-39535—25.6%
——8——CVE-2016-5026—25.6%
——8——CVE-2022-36462—25.6%
——8——CVE-2025-2136—25.6%
——8——CVE-2026-347808.3 HIG25.6%
——8Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in the main world (for example, via XSS) can use a bridged VideoFrame to gain access to the isolated world, including any Node.js APIs exposed to the preload script. Apps are only affected if a preload script returns, resolves, or passes a VideoFrame object to the main world via contextBridge.exposeInMainWorld(). Apps that do not bridge VideoFrame objects are not affected. This issue has been patched in versions 39.8.0, 40.7.0, and 41.0.0-beta.8.53dCVE-2024-41706—25.6%
——8——CVE-2026-168275.9 MED25.6%
——8IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer.22dCVE-2016-6413—25.6%
——8——CVE-2026-130054.4 MED25.6%
——8The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.61dCVE-2019-10127—25.6%
——8——CVE-2025-50574—25.6%
——8——CVE-2025-30931—25.6%
——8——CVE-2024-30135—25.6%
——8——CVE-2025-5661—25.6%
——8——CVE-2026-544775.4 MED25.6%
——8The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.71dCVE-2026-597116.1 MED25.6%
——8showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page.70dCVE-2026-25921—25.6%
——8——CVE-2024-29040—25.6%
——8——CVE-2024-27000—25.6%
——8——CVE-2025-11923—25.6%
——8——CVE-2024-11379—25.6%
——8——CVE-2024-27183—25.6%
——8——CVE-2022-491607.5 HIG25.6%
——8In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix crash during module load unload test
During purex packet handling the driver was incorrectly freeing a
pre-allocated structure. Fix this by skipping that entry.
System crashed with the following stack during a module unload test.
Call Trace:
sbitmap_init_node+0x7f/0x1e0
sbitmap_queue_init_node+0x24/0x150
blk_mq_init_bitmaps+0x3d/0xa0
blk_mq_init_tags+0x68/0x90
blk_mq_alloc_map_and_rqs+0x44/0x120
blk_mq_alloc_set_map_and_rqs+0x63/0x150
blk_mq_alloc_tag_set+0x11b/0x230
scsi_add_host_with_dma.cold+0x3f/0x245
qla2x00_probe_one+0xd5a/0x1b80 [qla2xxx]
Call Trace with slub_debug and debug kernel:
kasan_report_invalid_free+0x50/0x80
__kasan_slab_free+0x137/0x150
slab_free_freelist_hook+0xc6/0x190
kfree+0xe8/0x2e0
qla2x00_free_device+0x3bb/0x5d0 [qla2xxx]
qla2x00_remove_one+0x668/0xcf0 [qla2xxx]42dCVE-2020-23563—25.6%
——8——CVE-2024-49393—25.6%
——8——