Vulnerabilities exploitable today
369,392in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,099
- High7,540
- Medium5,594
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-44502—20.8%
——6——CVE-2023-541297.1 HIG20.8%
——6In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: Add validation for lmac type
Upon physical link change, firmware reports to the kernel about the
change along with the details like speed, lmac_type_id, etc.
Kernel derives lmac_type based on lmac_type_id received from firmware.
In a few scenarios, firmware returns an invalid lmac_type_id, which
is resulting in below kernel panic. This patch adds the missing
validation of the lmac_type_id field.
Internal error: Oops: 96000005 [#1] PREEMPT SMP
[ 35.321595] Modules linked in:
[ 35.328982] CPU: 0 PID: 31 Comm: kworker/0:1 Not tainted
5.4.210-g2e3169d8e1bc-dirty #17
[ 35.337014] Hardware name: Marvell CN103XX board (DT)
[ 35.344297] Workqueue: events work_for_cpu_fn
[ 35.352730] pstate: 40400089 (nZcv daIf +PAN -UAO)
[ 35.360267] pc : strncpy+0x10/0x30
[ 35.366595] lr : cgx_link_change_handler+0x90/0x18034dCVE-2025-48119—20.8%
——6——CVE-2019-0073—20.8%
——6——CVE-2025-5720—20.8%
——6——CVE-2025-24456—20.8%
——6——CVE-2025-52893—20.8%
——6——CVE-2024-53243—20.8%
——6——CVE-2024-11790—20.8%
——6——CVE-2026-138186.5 MED20.8%
——6Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)67dCVE-2025-1690—20.8%
——6——CVE-2017-16556—20.8%
——6——CVE-2020-3594—20.8%
——6——CVE-2026-456387.8 HIG20.8%
——6Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.46dCVE-2025-15095—20.8%
——6——CVE-2025-20167—20.8%
——6——CVE-2025-12135—20.8%
——6——CVE-2025-61730—20.8%
——6——CVE-2026-139536.5 MED20.8%
——6Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)67dCVE-2021-33098—20.8%
——6——CVE-2026-817775.3 MED20.8%
——6Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.
This issue affects Essential Addons for Elementor: from n/a through 6.8.0.10dCVE-2025-15392—20.8%
——6——CVE-2026-13508—20.8%
——6——CVE-2026-200147.7 HIG20.8%
——6A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network.
This vulnerability is due to the improper processing of IKEv2 packets. An attacker could exploit this vulnerability by sending crafted, authenticated IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust memory, causing the device to reload.27dCVE-2026-455937.8 HIG20.8%
——6Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.46dCVE-2020-3600—20.8%
——6——CVE-2017-3741—20.8%
——6——CVE-2026-26153—20.8%
——6——CVE-2023-28523—20.8%
——6——CVE-2024-13902—20.8%
——6——CVE-2024-56445—20.8%
——6——CVE-2025-69287—20.8%
——6——CVE-2025-70129—20.8%
——6——CVE-2026-187205.3 MED20.8%
——6A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.26dCVE-2020-8016—20.8%
——6——CVE-2025-29710—20.8%
——6——CVE-2025-30613—20.8%
——6——CVE-2026-170708.8 HIG20.8%
——6Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Liman MYS: from 2.2.3 before 2.3.1.12dCVE-2023-52072—20.8%
——6——CVE-2023-50770—20.8%
——6——