Vulnerabilities exploitable today
369,271in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,152
- High7,655
- Medium5,617
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2011-2242—20.1%
——6——CVE-2024-38811—20.1%
——6——CVE-2025-397207.5 HIG20.1%
——6In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix refcount leak causing resource not released
When ksmbd_conn_releasing(opinfo->conn) returns true,the refcount was not
decremented properly, causing a refcount leak that prevents the count from
reaching zero and the memory from being released.38dCVE-2026-162537.5 HIG20.1%
——6The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing them to disclose sensitive backup information and to force a full site restore that overwrites the live site's files and database. This is an incomplete fix of CVE-2020-36848, as the protection added at the time never took effect on distributed copies of the plugin.3dCVE-2010-4591—20.1%
——6——CVE-2017-15038—20.1%
——6——CVE-2026-57310—20.1%
——6Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash to decode user credentials.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.45dCVE-2024-37544—20.1%
——6——CVE-2026-72004.3 MED20.1%
——6A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /index.php?page=types. Executing a manipulation of the argument ID can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.44dCVE-2025-27561—20.1%
——6——CVE-2026-35645—20.1%
——6——CVE-2026-536686.9 MED20.1%
——6React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.34dCVE-2016-0394—20.1%
——6——CVE-2023-0551—20.1%
——6——CVE-2026-592535.0 MED20.1%
——6n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folders in other projects. Attackers can bypass project and folder authorization boundaries by supplying crafted request payloads during workflow creation, causing logical integrity violations in target project folder structures.60dCVE-2020-1708—20.1%
——6——CVE-2026-175894.9 MED20.1%
——6The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: the payload is written to the ec_pageoption table via the ec_ajax_save_page_options handler — which applies no sanitization to raw $_POST values — and is later retrieved with stripslashes() (bypassing WordPress magic-quotes protection) before being concatenated directly into SQL on every store page render.4dCVE-2024-10614—20.1%
——6——CVE-2022-50740—20.1%
——6——CVE-2024-54474—20.1%
——6——CVE-2025-9688—20.1%
——6——CVE-2026-3149—20.1%
——6——CVE-2022-32781—20.1%
——6——CVE-2023-34371—20.1%
——6——CVE-2026-57942—20.1%
——6——CVE-2024-2405—20.1%
——6——CVE-2025-58006—20.1%
——6——CVE-2023-6491—20.1%
——6——CVE-2025-27565—20.1%
——6——CVE-2025-41681—20.1%
——6——CVE-2022-50829—20.1%
——6——CVE-2022-50773—20.1%
——6——CVE-2022-31467—20.1%
——6——CVE-2025-13358—20.1%
——6——CVE-2025-68944—20.1%
——6——CVE-2024-49900—20.1%
——6——CVE-2023-535977.5 HIG20.1%
——6In the Linux kernel, the following vulnerability has been resolved:
cifs: fix mid leak during reconnection after timeout threshold
When the number of responses with status of STATUS_IO_TIMEOUT
exceeds a specified threshold (NUM_STATUS_IO_TIMEOUT), we reconnect
the connection. But we do not return the mid, or the credits
returned for the mid, or reduce the number of in-flight requests.
This bug could result in the server->in_flight count to go bad,
and also cause a leak in the mids.
This change moves the check to a few lines below where the
response is decrypted, even of the response is read from the
transform header. This way, the code for returning the mids
can be reused.
Also, the cifs_reconnect was reconnecting just the transport
connection before. In case of multi-channel, this may not be
what we want to do after several timeouts. Changed that to
reconnect the session and the tree too.
Also renamed NUM_STATUS_IO_TIMEOUT to a more appropriate name
MAX_STATUS_IO_TIMEOUT.33dCVE-2023-3841—20.1%
——6——CVE-2025-59008—20.1%
——6——CVE-2025-69243—20.1%
——6——