Vulnerabilities exploitable today
369,332in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,107
- High7,541
- Medium5,581
- Low536
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-25124—20.6%
——6——CVE-2026-140524.3 MED20.6%
——6Insufficient policy enforcement in FileSystem in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)67dCVE-2024-48021—20.6%
——6——CVE-2026-563653.7 LOW20.6%
——6ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.66dCVE-2025-611639.8 CRI20.6%
——6Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.3dCVE-2018-25381—20.6%
——6——CVE-2025-68033—20.6%
——6——CVE-2025-64185—20.6%
——6——CVE-2025-12461—20.6%
——6——CVE-2026-480608.1 HIG20.6%
——6Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from automatic escaping by the template engine when configured inline with documentation recommendations. This issue has been patched in version 2.20.0.38dCVE-2024-3124—20.6%
——6——CVE-2025-445266.5 MED20.6%
——6Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_Req packet.63dCVE-2026-52796—20.6%
——6——CVE-2011-0532—20.6%
——6——CVE-2023-44385—20.6%
——6——CVE-2026-55409—20.6%
——6——CVE-2026-658799.8 CRI20.6%
——6Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.40dCVE-2024-47624—20.6%
——6——CVE-2025-41016—20.6%
——6——CVE-2022-42309—20.6%
——6——CVE-2022-49350—20.6%
——6——CVE-2026-718456.3 MED20.6%
——6A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every startup. An attacker with access to pod logs or centralized logging could obtain the credential, leading to unauthorized access to the CCX API.1dCVE-2026-35716.5 MED20.6%
——6The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to change registration form status.44dCVE-2026-5494—20.6%
——6——CVE-2025-14896—20.6%
——6——CVE-2012-4508—20.6%
——6——CVE-2021-47969—20.6%
——6——CVE-2025-21561—20.6%
——6——CVE-2025-67931—20.6%
——6——CVE-2025-3964—20.6%
——6——CVE-2026-584398.1 HIG20.6%
——6Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag11dCVE-2025-13381—20.6%
——6——CVE-2023-28072—20.6%
——6——CVE-2023-31669—20.6%
——6——CVE-2025-25127—20.6%
——6——CVE-2025-30464—20.6%
——6——CVE-2021-47970—20.6%
——6——CVE-2026-567109.8 CRI20.6%
——6Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.6dCVE-2025-23530—20.6%
——6——CVE-2024-49201—20.6%
——6——