Vulnerabilities exploitable today
372,926in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,236
- High8,261
- Medium6,234
- Low615
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-10731—23.8%
——7——CVE-2022-38658—23.8%
——7——CVE-2008-5450—23.8%
——7——CVE-2021-33655—23.8%
——7——CVE-2022-43653—23.8%
——7——CVE-2024-9835—23.8%
——7——CVE-2025-61613—23.8%
——7——CVE-2025-11851—23.8%
——7——CVE-2025-61612—23.8%
——7——CVE-2026-143659.8 CRI23.8%
——7The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts.30dCVE-2025-64658—23.8%
——7——CVE-2006-6441—23.8%
——7——CVE-2026-739357.5 HIG23.8%
——7Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).14dCVE-2025-37840—23.8%
——7——CVE-2024-6024—23.8%
——7——CVE-2024-34373—23.8%
——7——CVE-2010-2199—23.8%
——7——CVE-2023-29426—23.8%
——7——CVE-2022-3303—23.8%
——7——CVE-2026-792936.5 MED23.8%
——7Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)15dCVE-2022-32654—23.8%
——7——CVE-2025-5464—23.8%
——7——CVE-2024-267737.8 HIG23.8%
——7In the Linux kernel, the following vulnerability has been resolved:
ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found()
Determine if the group block bitmap is corrupted before using ac_b_ex in
ext4_mb_try_best_found() to avoid allocating blocks from a group with a
corrupted block bitmap in the following concurrency and making the
situation worse.
ext4_mb_regular_allocator
ext4_lock_group(sb, group)
ext4_mb_good_group
// check if the group bbitmap is corrupted
ext4_mb_complex_scan_group
// Scan group gets ac_b_ex but doesn't use it
ext4_unlock_group(sb, group)
ext4_mark_group_bitmap_corrupted(group)
// The block bitmap was corrupted during
// the group unlock gap.
ext4_mb_try_best_found
ext4_lock_group(ac->ac_sb, group)
ext4_mb_use_best_found
mb_mark_used
// Allocating blocks in block bitmap corrupted group39dCVE-2024-27024—23.8%
——7——CVE-2025-49215—23.8%
——7——CVE-2026-42184—23.8%
——7——CVE-2023-45958—23.8%
——7——CVE-2026-1897—23.8%
——7——CVE-2022-47664—23.8%
——7——CVE-2023-37571—23.8%
——7——CVE-2007-4598—23.8%
——7——CVE-2024-11052—23.8%
——7——CVE-2023-5585—23.8%
——7——CVE-2024-10515—23.8%
——7——CVE-2025-10915—23.8%
——7——CVE-2026-792716.5 MED23.8%
——7Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)11dCVE-2025-63422—23.8%
——7——CVE-2020-37093—23.8%
——7——CVE-2001-1415—23.8%
——7——CVE-2023-498999.8 CRI23.8%
——7An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.56d