Vulnerabilities exploitable today
369,220in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,158
- High7,703
- Medium5,629
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-20514—19.8%
——6——CVE-2024-20534—19.8%
——6——CVE-2024-32784—19.8%
——6——CVE-2025-63447—19.8%
——6——CVE-2025-63448—19.8%
——6——CVE-2025-11725—19.8%
——6——CVE-2022-50715—19.8%
——6——CVE-2026-790154.3 MED19.8%
——6Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)8dCVE-2024-47684—19.8%
——6——CVE-2024-49944—19.8%
——6——CVE-2025-43759—19.8%
——6——CVE-2025-6081—19.8%
——6——CVE-2024-41910—19.8%
——6——CVE-2024-34803—19.8%
——6——CVE-2022-25770—19.8%
——6——CVE-2026-4236—19.8%
——6——CVE-2021-39048—19.8%
——6——CVE-2024-35646—19.8%
——6——CVE-2026-0996—19.8%
——6——CVE-2026-324668.5 HIG19.8%
——6Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.16dCVE-2025-22346—19.8%
——6——CVE-2017-14317—19.8%
——6——CVE-2023-54045—19.8%
——6——CVE-2026-345329.1 CRI19.8%
——6Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. When a Cloud Function handler is declared using the function keyword and its validator is a plain object or arrow function, the trigger store traversal resolves the handler through its own prototype chain while the validator store fails to mirror this traversal, causing all access control enforcement to be skipped. This allows unauthenticated callers to invoke Cloud Functions that are meant to be protected by validators such as requireUser, requireMaster, or custom validation logic. This issue has been patched in versions 8.6.67 and 9.7.0-alpha.11.43dCVE-2026-324788.5 HIG19.8%
——6Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.12dCVE-2026-72067.3 HIG19.8%
——6A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_json of the file src/entry.py. Performing a manipulation of the argument output_filename results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The patch is named a5580cb992f4f6c308c9ffe6442b2e76709db548. Applying a patch is the recommended action to fix this issue.43dCVE-2014-9710—19.8%
——6——CVE-2024-472734.3 MED19.8%
——6An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.45dCVE-2024-12476—19.8%
——6——CVE-2026-683738.1 HIG19.8%
——6In the Linux kernel, the following vulnerability has been resolved:
wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
at76_guess_freq() checks only that the received frame is at least a bare
802.11 header (24 bytes) before subtracting the fixed management-body
offset:
len -= el_off;
For both beacon and probe response frames, el_off is 36. If the frame is
shorter than el_off, subtracting it causes the calculated IE length to
wrap. The length is eventually passed to cfg80211_find_elem_match() as a
very large unsigned value, so the element walk runs beyond the RX skb.
This path is reached from at76_rx_tasklet() while scanning. If the device
delivers a truncated beacon or probe response, the oversized IE length
causes an out-of-bounds read during scanning.
Skip the IE lookup if the frame does not reach the variable elements,
before subtracting el_off.17dCVE-2022-42815—19.8%
——6——CVE-2024-32787—19.8%
——6——CVE-2024-32783—19.8%
——6——CVE-2025-40742—19.8%
——6——CVE-2020-18768—19.8%
——6——CVE-2022-496457.8 HIG19.8%
——6In the Linux kernel, the following vulnerability has been resolved:
drm/panfrost: Fix shrinker list corruption by madvise IOCTL
Calling madvise IOCTL twice on BO causes memory shrinker list corruption
and crashes kernel because BO is already on the list and it's added to
the list again, while BO should be removed from the list before it's
re-added. Fix it.32dCVE-2025-14397—19.8%
——6——CVE-2022-38704—19.8%
——6——CVE-2023-5962—19.8%
——6——CVE-2024-22134—19.8%
——6——