Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,229
- High8,271
- Medium6,309
- Low606
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-99418.8 HIG22.8%
——7Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)51dCVE-2024-9172—22.8%
——7——CVE-2022-39210—22.8%
——7——CVE-2026-26982—22.8%
——7——CVE-2026-99278.8 HIG22.8%
——7Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)51dCVE-2021-32658—22.8%
——7——CVE-2024-49953—22.8%
——7——CVE-2026-635277.8 HIG22.8%
——7Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.28dCVE-2026-354788.3 HIG22.8%
——7InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system — including administrators and superusers — by supplying the target's user ID in the user field of a POST /api/user/tokens/ request. The returned token is immediately usable for full API authentication as the target user, from any network location, with no further interaction required. This vulnerability is fixed in 1.2.7 and 1.3.0.48dCVE-2025-30466—22.8%
——7——CVE-2026-703117.8 HIG22.8%
——7Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.27dCVE-2026-8780—22.8%
——7——CVE-2025-2829—22.8%
——7——CVE-2025-2288—22.8%
——7——CVE-2026-42318—22.8%
——7GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. As a workaround, disable delete rights for User's planning.20dCVE-2026-162569.8 CRI22.8%
——7The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.15dCVE-2023-50822—22.8%
——7——CVE-2026-688077.8 HIG22.8%
——7Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.28dCVE-2018-6683—22.8%
——7——CVE-2025-46632—22.8%
——7——CVE-2026-613164.3 MED22.8%
——7Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).30dCVE-2023-50834—22.8%
——7——CVE-2025-3288—22.8%
——7——CVE-2026-8781—22.8%
——7——CVE-2016-6449—22.8%
——7——CVE-2026-58668.8 HIG22.8%
——7Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)48dCVE-2026-64852—22.8%
——7Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.8, the Grav API plugin intercepts the apiKeyGenerate and apiKeyRevoke admin tasks in user/plugins/api/api.php and authorizes the caller with only admin.login. A basic panel user can select another account from the route, create a persistent ApiKeyManager credential bound to that target, and inherit the target's API permissions, including api.super or administrative write access when present. This issue is fixed in version 1.0.8.22hCVE-2021-404907.0 HIG22.8%
——7A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.28dCVE-2023-28517—22.8%
——7——CVE-2026-649127.8 HIG22.8%
——7Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.27dCVE-2026-649207.8 HIG22.8%
——7Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.27dCVE-2026-649067.8 HIG22.8%
——7Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.27dCVE-2026-141829.8 CRI22.8%
——7The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.15dCVE-2017-14772—22.8%
——7——CVE-2023-2717—22.8%
——7——CVE-2026-435710.0 CRI22.8%
——7The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.7dCVE-2020-27830—22.8%
——7——CVE-2026-446185.3 MED22.8%
——7Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.49dCVE-2025-1672—22.8%
——7——CVE-2026-8782—22.8%
——7——