Vulnerabilities exploitable today
373,224in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,252
- High8,221
- Medium6,136
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-68163.8 LOW24.9%
——7An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users.
This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.55dCVE-2025-41760—24.9%
——7——CVE-2025-6080—24.9%
——7——CVE-2024-3732—24.9%
——7——CVE-2025-41759—24.9%
——7——CVE-2024-2031—24.9%
——7——CVE-2025-1799—24.9%
——7——CVE-2026-191613.1 LOW24.9%
——7Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)38dCVE-2024-38687—24.9%
——7——CVE-2026-33524—24.9%
——7——CVE-2024-46657—24.9%
——7——CVE-2026-398757.8 HIG24.9%
——7A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.40dCVE-2025-8402—24.9%
——7——CVE-2026-790023.1 LOW24.9%
——7Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)17dCVE-2024-32791—24.9%
——7——CVE-2025-62619—24.9%
——7——CVE-2024-24831—24.9%
——7——CVE-2024-582409.8 CRI24.9%
——7In the Linux kernel, the following vulnerability has been resolved:
tls: separate no-async decryption request handling from async
If we're not doing async, the handling is much simpler. There's no
reference counting, we just need to wait for the completion to wake us
up and return its result.
We should preferably also use a separate crypto_wait. I'm not seeing a
UAF as I did in the past, I think aec7961916f3 ("tls: fix race between
async notify and socket close") took care of it.
This will make the next fix easier.26dCVE-2024-7347—24.9%
——7——CVE-2019-25320—24.9%
——7——CVE-2020-1824—24.9%
——7——CVE-2019-8453—24.9%
——7——CVE-2024-3245—24.9%
——7——CVE-2016-4678—24.9%
——7——CVE-2025-1561—24.9%
——7——CVE-2026-22216—24.9%
——7——CVE-2026-76565—24.9%
——7Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.725dCVE-2025-34504—24.9%
——7——CVE-2023-32551—24.9%
——7——CVE-2025-22212—24.9%
——7——CVE-2020-27902—24.9%
——7——CVE-2026-42571—24.9%
——7Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). This attack allows any user authenticated to the WebUI via OAuth to gain admin privileges under certain configurations. This issue has been patched in versions 7.21.5, 7.22.3, 7.23.3, and 7.24.2.51dCVE-2026-45104—24.9%
——7——CVE-2025-68270—24.9%
——7——CVE-2026-544115.9 MED24.9%
——7Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.35dCVE-2024-13873—24.9%
——7——CVE-2024-13377—24.9%
——7——CVE-2024-49706—24.9%
——7——CVE-2023-26328—24.9%
——7——CVE-2020-0188—24.9%
——7——