Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-5937—25.4%
——8——CVE-2026-33082—25.4%
——8——CVE-2025-31952—25.4%
——8——CVE-2024-25445—25.4%
——8——CVE-2026-96036.5 MED25.4%
——8A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.53dCVE-2025-47056—25.4%
——8——CVE-2026-614468.4 HIG25.4%
——8PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Python (.py) files from project-level and user-home .praisonai/plugins/ directories using importlib spec_from_file_location() and exec_module() without code signing, integrity verification, or sandboxing. An attacker who can write a malicious .py file to a plugin directory (for example via path traversal, a supply chain attack, or a compromised dependency) achieves arbitrary code execution when the plugin system initializes.62dCVE-2025-47048—25.4%
——8——CVE-2025-47050—25.4%
——8——CVE-2026-109749.6 CRI25.4%
——8Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)55dCVE-2026-110659.6 CRI25.4%
——8Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)54dCVE-2026-579454.3 MED25.4%
——8PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Attackers can exploit the missing session-to-user identifier validation in the PUT users API endpoint to overwrite another user's profile details without authorization.63dCVE-2025-2593—25.4%
——8——CVE-2026-22762—25.4%
——8——CVE-2024-3127—25.4%
——8——CVE-2026-874929.6 CRI25.4%
——8Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)5dCVE-2026-729618.2 HIG25.4%
——8Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.6dCVE-2026-108929.6 CRI25.4%
——8Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)55dCVE-2026-41133—25.4%
——8——CVE-2025-66869—25.4%
——8——CVE-2026-627696.7 MED25.4%
——8Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.29dCVE-2026-110219.6 CRI25.4%
——8Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)55dCVE-2026-93584.3 MED25.4%
——8A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 6.1.3 and 7.1.3 is able to address this issue. This patch is called 5bc698cef66f8abd12610dc623e5d67cbc0f869d. It is suggested to upgrade the affected component. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)." The commits were backported to 6.x branch, which was the most downloaded version.54dCVE-2025-47060—25.4%
——8——CVE-2025-22460—25.4%
——8——CVE-2026-109839.6 CRI25.4%
——8Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)55dCVE-2024-30296—25.4%
——8——CVE-2026-25131—25.4%
——8——CVE-2020-13358—25.4%
——8——CVE-2026-44672—25.4%
——8——CVE-2026-108978.8 HIG25.4%
——8Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)55dCVE-2026-698468.2 HIG25.4%
——8Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.2hCVE-2020-27129—25.4%
——8——CVE-2022-47665—25.4%
——8——CVE-2024-456194.3 MED25.4%
——8A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.77dCVE-2026-601348.8 HIG25.4%
——8Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.47dCVE-2020-10268—25.4%
——8——CVE-2025-68022—25.4%
——8——CVE-2025-400468.6 HIG25.4%
——8In the Linux kernel, the following vulnerability has been resolved:
io_uring/zcrx: fix overshooting recv limit
It's reported that sometimes a zcrx request can receive more than was
requested. It's caused by io_zcrx_recv_skb() adjusting desc->count for
all received buffers including frag lists, but then doing recursive
calls to process frag list skbs, which leads to desc->count double
accounting and underflow.47dCVE-2026-190936.8 MED25.4%
——8The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root.
The readable files include the WordPress configuration file, which exposes the database credentials and the authentication keys and salts, so authentication cookies can be forged.23d