Vulnerabilities exploitable today
371,523in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,605
- Medium6,350
- Low586
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-47559—22.1%
——7——CVE-2023-32089—22.1%
——7——CVE-2026-492277.6 HIG22.1%
——7Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment operations allow a low-privileged Author to manage comments under another Author's posts. The admin/controller/content/comment.php and admin/controller/content/comments.php controllers and the admin/sql/sqlite/comment.sql queries accept a caller-controlled comment_id without verifying comment.post_id against post.admin_id for the current admin_id. An attacker can read pending comment content and commenter email addresses, change moderation status, edit comment content, or delete comments, breaking author and moderation boundaries. This issue is fixed in version 1.0.8.4.13hCVE-2023-26085—22.1%
——7——CVE-2023-32088—22.1%
——7——CVE-2023-42436—22.1%
——7——CVE-2025-66495—22.1%
——7——CVE-2025-60800—22.1%
——7——CVE-2024-21738—22.1%
——7——CVE-2026-35669—22.1%
——7——CVE-2025-10256—22.1%
——7——CVE-2026-684728.1 HIG22.1%
——7In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: validate EHT MLE before MLD ID read
cfg80211_gen_new_ie() copies ML probe response elements from
the parent frame when the parent EHT multi-link element has an
MLD ID matching the nontransmitted BSSID index.
The code only checked that the extension element had more than
one byte before calling ieee80211_mle_get_mld_id(). That helper
assumes a BASIC MLE with enough common info and documents that
callers must first use ieee80211_mle_type_ok().
Attack chain:
malicious AP sends a short EHT MLE in an MBSSID beacon.
cfg80211_inform_bss_frame_data() stores the copied IE buffer.
cfg80211_parse_mbssid_data() builds the nontransmitted BSS IE.
cfg80211_gen_new_ie() sees the EHT MLE in the parent frame.
ieee80211_mle_get_mld_id() then reads past the IE boundary.
Validate the MLE type and size before reading the MLD ID. This
matches the contract required by the MLE helper and rejects the
short element before any internal MLE fields are accessed.23dCVE-2020-24500—22.1%
——7——CVE-2026-168785.4 MED22.1%
——7IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.23dCVE-2010-5159—22.1%
——7——CVE-2010-5169—22.1%
——7——CVE-2026-27919—22.1%
——7——CVE-2024-45306—22.1%
——7——CVE-2025-60595—22.1%
——7——CVE-2010-4415—22.1%
——7——CVE-2026-790326.8 MED22.1%
——7Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)9dCVE-2025-36134—22.1%
——7——CVE-2021-27046—22.1%
——7——CVE-2024-47610—22.1%
——7——CVE-2025-69313—22.1%
——7——CVE-2026-83915.3 MED22.1%
——7Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.56dCVE-2024-55570—22.1%
——7——CVE-2024-2301—22.1%
——7——CVE-2025-32354—22.1%
——7——CVE-2006-7162—22.1%
——7——CVE-2025-53768—22.1%
——7——CVE-2019-20663—22.1%
——7——CVE-2024-49828—22.1%
——7——CVE-2024-9663—22.1%
——7——CVE-2026-35158.5 HIG22.1%
——7A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, leading to potential Server-Side Request Forgery (SSRF), credential theft, or remote code execution (RCE). The vulnerability affects both the `aget_directory()` and `get_directory()` methods in `src/integrations/prefect-github/prefect_github/repository.py`. This issue does not affect the GitLab and BitBucket integrations, which use a safer list-based command construction approach.48dCVE-2024-50353—22.1%
——7——CVE-2020-15710—22.1%
——7——CVE-2024-9238—22.1%
——7——CVE-2023-50712—22.1%
——7——CVE-2026-570887.8 HIG22.1%
——7Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.48d