Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low585
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-789686.5 MED22.0%
——7Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially spoof address bar via a crafted HTML page. (Chromium security severity: Low)13dCVE-2026-22492—22.0%
——7——CVE-2014-5797—22.0%
——7——CVE-2023-31921—22.0%
——7——CVE-2024-20887—22.0%
——7——CVE-2014-5740—22.0%
——7——CVE-2014-6662—22.0%
——7——CVE-2014-5787—22.0%
——7——CVE-2025-5284—22.0%
——7——CVE-2024-323875.7 MED22.0%
——7An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component.54dCVE-2025-47872—22.0%
——7——CVE-2025-46335—22.0%
——7——CVE-2014-6693—22.0%
——7——CVE-2014-5761—22.0%
——7——CVE-2026-704948.1 HIG22.0%
——7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete chats and messages belonging to the folder owner. The cascade following the authorization check is bound to the folder owner's id, but the subfolder check accepted any inherited write grant instead of requiring ownership or administrator status. A collaborator can destroy the owner's subtree or force-move chats out of it when delete_contents=false. This issue is fixed in 0.11.0.10hCVE-2014-5758—22.0%
——7——CVE-2025-52534—22.0%
——7——CVE-2014-5785—22.0%
——7——CVE-2014-5686—22.0%
——7——CVE-2014-6015—22.0%
——7——CVE-2014-5789—22.0%
——7——CVE-2014-5980—22.0%
——7——CVE-2014-6001—22.0%
——7——CVE-2024-385527.3 HIG22.0%
——7In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix potential index out of bounds in color transformation function
Fixes index out of bounds issue in the color transformation function.
The issue could occur when the index 'i' exceeds the number of transfer
function points (TRANSFER_FUNC_POINTS).
The fix adds a check to ensure 'i' is within bounds before accessing the
transfer function points. If 'i' is out of bounds, an error message is
logged and the function returns false to indicate an error.
Reported by smatch:
drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:405 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max
drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:406 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max
drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:407 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max36dCVE-2014-5784—22.0%
——7——CVE-2014-6653—22.0%
——7——CVE-2014-5741—22.0%
——7——CVE-2024-56279—22.0%
——7——CVE-2014-5953—22.0%
——7——CVE-2017-1124—22.0%
——7——CVE-2014-5569—22.0%
——7——CVE-2014-5822—22.0%
——7——CVE-2025-14428—22.0%
——7——CVE-2026-22011—22.0%
——7——CVE-2026-54885.3 MED22.0%
——7The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin pages (including profile.php which subscribers can access), and while other similar AJAX endpoints in the same class properly check for the exactmetrics_save_settings capability, these two endpoints only verify the nonce. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve valid Google Ads access tokens and reset Google Ads integration settings.25dCVE-2025-7727—22.0%
——7——CVE-2014-5781—22.0%
——7——CVE-2014-5738—22.0%
——7——CVE-2023-45359—22.0%
——7——CVE-2025-30429—22.0%
——7——