Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,229
- High8,265
- Medium6,309
- Low606
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-688117.8 HIG22.8%
——7Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.28dCVE-2026-141829.8 CRI22.8%
——7The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.15dCVE-2015-4946—22.8%
——7——CVE-2026-108756.3 MED22.8%
——7A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unknown function of the file /admin/adminHome.ph. The manipulation of the argument social_twitter results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.50dCVE-2026-446185.3 MED22.8%
——7Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.49dCVE-2026-435710.0 CRI22.8%
——7The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.7dCVE-2017-14772—22.8%
——7——CVE-2026-179188.8 HIG22.8%
——7Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)38dCVE-2025-11165—22.8%
——7——CVE-2024-12465—22.8%
——7——CVE-2025-62413—22.8%
——7——CVE-2017-8185—22.8%
——7——CVE-2026-58798.8 HIG22.8%
——7Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)48dCVE-2023-29067—22.8%
——7——CVE-2026-58728.8 HIG22.8%
——7Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)48dCVE-2024-9242—22.8%
——7——CVE-2026-58628.8 HIG22.8%
——7Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)48dCVE-2019-11836—22.8%
——7——CVE-2024-40875—22.8%
——7——CVE-2021-0204—22.8%
——7——CVE-2025-2293—22.8%
——7——CVE-2019-8579—22.8%
——7——CVE-2022-40476—22.8%
——7——CVE-2026-649197.8 HIG22.8%
——7Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.27dCVE-2026-688107.8 HIG22.8%
——7Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.28dCVE-2026-839398.2 HIG22.8%
——7Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.1dCVE-2026-604084.3 MED22.8%
——7Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized read access to a subset of TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).41dCVE-2023-44464—22.8%
——7——CVE-2025-67482—22.8%
——7——CVE-2011-4363—22.8%
——7——CVE-2013-1610—22.8%
——7——CVE-2026-108746.3 MED22.8%
——7A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown function of the file /admin/adminHome.php. The manipulation of the argument social_insta leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.50dCVE-2021-39198—22.8%
——7——CVE-2026-688157.8 HIG22.8%
——7Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.28dCVE-2026-649057.8 HIG22.8%
——7Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.27dCVE-2024-37942—22.8%
——7——CVE-2026-99418.8 HIG22.8%
——7Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)51dCVE-2026-26982—22.8%
——7——CVE-2018-6683—22.8%
——7——CVE-2026-99278.8 HIG22.8%
——7Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)51d