Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,221
- High8,140
- Medium6,165
- Low607
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2007-6340—22.8%
——7——CVE-2026-485757.9 HIG22.8%
——7Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.50dCVE-2026-183247.2 HIG22.8%
——7The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted Textarea field has the Rich-Text editor option enabled.13dCVE-2024-4226—22.8%
——7——CVE-2025-7799—22.8%
——7——CVE-2025-68505—22.8%
——7——CVE-2016-0206—22.8%
——7——CVE-2025-24938—22.8%
——7——CVE-2024-38037—22.8%
——7——CVE-2025-55098—22.8%
——7——CVE-2025-13318—22.8%
——7——CVE-2023-49344—22.8%
——7——CVE-2026-455887.9 HIG22.8%
——7Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.50dCVE-2026-34272—22.8%
——7——CVE-2024-9708—22.8%
——7——CVE-2023-32365—22.8%
——7——CVE-2021-4218—22.8%
——7——CVE-2025-10641—22.8%
——7——CVE-2026-501959.9 CRI22.8%
——7containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequently, if other pods on the same node attempt to use the poisoned tag with an IfNotPresent (or Never) pull policy, they will unknowingly execute the attacker's malicious image instead of the legitimate one. This can lead to a compromise of the affected pods, allowing the attacker to execute arbitrary code under the victim pod's identity. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.70dCVE-2025-30179—22.8%
——7——CVE-2026-646217.3 HIG22.8%
——7FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration.44dCVE-2021-32001—22.8%
——7——CVE-2024-08304.3 MED22.8%
——7The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on several ajax actions. This makes it possible for unauthenticated attackers to invoke those actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. As a result, they may modify comment form fields and update plugin settings.30dCVE-2024-10168—22.8%
——7——CVE-2026-73213—22.8%
——7Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an IPv6 peer that is numerically within a configured non-prefix-aligned denied-peer-ip range but is classified as outside it. This issue is fixed in version 4.16.0.1dCVE-2026-592263.1 LOW22.8%
——7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automations, and check_model_access only enforced private-model grants for the exact user role, allowing deactivated pending users to continue scheduled model execution. This issue is fixed in version 0.10.0.63dCVE-2024-49773—22.8%
——7——CVE-2024-1219—22.8%
——7——CVE-2025-12349—22.8%
——7——CVE-2023-3262—22.8%
——7——CVE-2024-9072—22.8%
——7——CVE-2023-541208.8 HIG22.8%
——7In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: Fix race condition in hidp_session_thread
There is a potential race condition in hidp_session_thread that may
lead to use-after-free. For instance, the timer is active while
hidp_del_timer is called in hidp_session_thread(). After hidp_session_put,
then 'session' will be freed, causing kernel panic when hidp_idle_timeout
is running.
The solution is to use del_timer_sync instead of del_timer.
Here is the call trace:
? hidp_session_probe+0x780/0x780
call_timer_fn+0x2d/0x1e0
__run_timers.part.0+0x569/0x940
hidp_session_probe+0x780/0x780
call_timer_fn+0x1e0/0x1e0
ktime_get+0x5c/0xf0
lapic_next_deadline+0x2c/0x40
clockevents_program_event+0x205/0x320
run_timer_softirq+0xa9/0x1b0
__do_softirq+0x1b9/0x641
__irq_exit_rcu+0xdc/0x190
irq_exit_rcu+0xe/0x20
sysvec_apic_timer_interrupt+0xa1/0xc037dCVE-2026-485707.9 HIG22.8%
——7Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.50dCVE-2026-26326—22.8%
——7——CVE-2025-9331—22.8%
——7——CVE-2024-1642—22.8%
——7——CVE-2023-39429—22.8%
——7——CVE-2019-4444—22.8%
——7——CVE-2026-27837—22.8%
——7——CVE-2025-8920—22.8%
——7——