Vulnerabilities exploitable today
372,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,279
- High8,418
- Medium6,481
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-395518.1 HIG23.3%
——7Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection.
This issue affects Töbel: from n/a through 1.8.1.51dCVE-2025-48011—23.3%
——7——CVE-2016-4005—23.3%
——7——CVE-2026-27098—23.3%
——7——CVE-2026-40752—23.3%
——7——CVE-2024-37258—23.3%
——7——CVE-2024-35734—23.3%
——7——CVE-2024-21607—23.3%
——7——CVE-2021-1441—23.3%
——7——CVE-2025-23798—23.3%
——7——CVE-2026-0481—23.3%
——7——CVE-2023-526567.8 HIG23.3%
——7In the Linux kernel, the following vulnerability has been resolved:
io_uring: drop any code related to SCM_RIGHTS
This is dead code after we dropped support for passing io_uring fds
over SCM_RIGHTS, get rid of it.38dCVE-2024-45458—23.3%
——7——CVE-2024-41876—23.3%
——7——CVE-2024-8494—23.3%
——7——CVE-2026-106087.3 HIG23.3%
——7A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.51dCVE-2024-56288—23.3%
——7——CVE-2026-23971—23.3%
——7——CVE-2007-3654—23.3%
——7——CVE-2026-40753—23.3%
——7——CVE-2022-0398—23.3%
——7——CVE-2025-2133—23.3%
——7——CVE-2025-48071—23.3%
——7——CVE-2025-5757—23.3%
——7——CVE-2025-52331—23.3%
——7——CVE-2026-189425.5 MED23.3%
——7A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the tenant administrative control over the Kubernetes cluster.23dCVE-2021-336267.8 HIG23.3%
——7A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.31dCVE-2024-10388—23.3%
——7——CVE-2026-43039—23.3%
——7——CVE-2024-13374—23.3%
——7——CVE-2020-12364—23.3%
——7——CVE-2024-23558—23.3%
——7——CVE-2024-43238—23.3%
——7——CVE-2024-38781—23.3%
——7——CVE-2020-27835—23.3%
——7——CVE-2026-28873—23.3%
——7——CVE-2025-55069—23.3%
——7——CVE-2025-27702—23.3%
——7——CVE-2026-745709.8 CRI23.3%
——7In the Linux kernel, the following vulnerability has been resolved:
ntfs: harden runlist realloc size calculations
Add a shared helper to safely convert runlist element counts to byte sizes
using overflow checks, and use it in both ntfs_rl_realloc() and
ntfs_rl_realloc_nofail().25dCVE-2026-156068.8 HIG23.3%
——7The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to reset the password of any user on the site, including administrators, leading to full account takeover and complete site compromise. Exploitation requires the attacker to hold a valid encrypted Current-User token obtained by accessing any Edit User form they are legitimately authorized to submit, which they then use as a known-plaintext base for the CBC bit-flipping forgery.30d