Vulnerabilities exploitable today
373,010in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,220
- High8,131
- Medium6,193
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-40673—24.3%
——7——CVE-2025-14050—24.3%
——7——CVE-2025-48741—24.3%
——7——CVE-2019-8642—24.3%
——7——CVE-2025-10470—24.3%
——7——CVE-2014-0646—24.3%
——7——CVE-2024-4224—24.3%
——7——CVE-2020-0584—24.3%
——7——CVE-2024-50558—24.3%
——7——CVE-2025-24689—24.3%
——7——CVE-2024-20865—24.3%
——7——CVE-2026-486178.2 HIG24.3%
——7A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.24dCVE-2023-6194—24.3%
——7——CVE-2025-3730—24.3%
——7——CVE-2023-49222—24.3%
——7——CVE-2025-20287—24.3%
——7——CVE-2024-3851—24.3%
——7——CVE-2026-131747.2 HIG24.3%
——7The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.24dCVE-2025-8627—24.3%
——7——CVE-2026-8296—24.3%
——7——CVE-2024-24857—24.3%
——7——CVE-2020-273396.7 MED24.3%
——7In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).32dCVE-2026-790654.3 MED24.3%
——7Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)12dCVE-2025-24559—24.3%
——7——CVE-2026-80907.3 HIG24.3%
——7Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.46dCVE-2023-51798—24.3%
——7——CVE-2007-1009—24.3%
——7——CVE-2024-53791—24.3%
——7——CVE-2025-15238—24.3%
——7——CVE-2025-49199—24.3%
——7——CVE-2017-5727—24.3%
——7——CVE-2026-198004.9 MED24.3%
——7The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The $wpdb->prepare() call does not protect against this injection because the attacker-controlled $contact_filter_query fragment is concatenated into the SQL format string before prepare() executes — prepare() only processes %s/%d placeholders and cannot sanitize content already embedded in the format string. REST API JSON bodies are parsed from php://input and bypass WordPress's wp_magic_quotes(), meaning double-quote characters in status array values reach the SQL sink unescaped. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The required 'mint_read_contacts' capability is a plugin-specific capability not assigned to any default WordPress role; it must be explicitly granted by an administrator, making this effectively an Administrator+ vulnerability.3dCVE-2026-8362—24.3%
——7——CVE-2021-1102—24.3%
——7——CVE-2025-14086—24.3%
——7——CVE-2026-155026.3 MED24.3%
——7A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php of the component PayPal IPN Payment Handler. The manipulation of the argument item_number results in sql injection. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.61dCVE-2025-46635—24.3%
——7——CVE-2025-0745—24.3%
——7——CVE-2026-154786.3 MED24.3%
——7A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employeeList can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.61dCVE-2026-26016—24.3%
——7——