Vulnerabilities exploitable today
369,308in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,126
- High7,588
- Medium5,599
- Low538
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-10014—19.9%
——6——CVE-2024-36406—19.9%
——6——CVE-2024-52998—19.9%
——6——CVE-2019-14477—19.9%
——6——CVE-2026-324668.5 HIG19.9%
——6Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.17dCVE-2023-41980—19.9%
——6——CVE-2026-487446.5 MED19.9%
——6Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the channelUpdate() mutation to change channel order settings such as allowUnpaidOrders even when the response reports PermissionDenied. The same permission utility can expose hidden objects through the pageType() and translation() queries, including attributes whose visibleInStorefront field is false and that should be visible only to users with management permissions. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22.18dCVE-2019-3588—19.9%
——6——CVE-2026-47182—19.9%
——6——CVE-2022-50728—19.9%
——6——CVE-2026-41708—19.9%
——6——CVE-2026-812878.5 HIG19.9%
——6Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.5dCVE-2024-34711—19.9%
——6——CVE-2026-4236—19.9%
——6——CVE-2024-8473—19.9%
——6——CVE-2025-49419—19.9%
——6——CVE-2022-40884—19.9%
——6——CVE-2026-99637.5 HIG19.9%
——6Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)47dCVE-2025-24234—19.9%
——6——CVE-2024-20504—19.9%
——6——CVE-2026-0890—19.9%
——6——CVE-2026-283855.0 MED19.9%
——6In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network infrastructure via the /images endpoint. When importing an image from a URL source, the LXD daemon fails to validate or restrict outbound destination IP addresses, allowing connections to loopback, RFC1918 private ranges, and cloud metadata endpoints. This enables error-based port scanning and unauthorized interaction with internal HTTP services from the daemon's network position.62dCVE-2026-44719—19.9%
——6——CVE-2023-52504—19.9%
——6——CVE-2026-396895.3 MED19.9%
——6Missing Authorization vulnerability in eshipper eShipper Commerce eshipper-commerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eShipper Commerce: from n/a through <= 2.16.12.44dCVE-2025-29573—19.9%
——6——CVE-2010-1973—19.9%
——6——CVE-2026-39579—19.9%
——6——CVE-2024-52919—19.9%
——6——CVE-2020-1836—19.9%
——6——CVE-2026-32111—19.9%
——6——CVE-2026-32326—19.9%
——6——CVE-2024-54176—19.9%
——6——CVE-2026-163798.8 HIG19.9%
——6Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.44dCVE-2026-139316.5 MED19.9%
——6Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)67dCVE-2021-30908—19.9%
——6——CVE-2026-44718—19.9%
——6——CVE-2024-409097.8 HIG19.9%
——6In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix a potential use-after-free in bpf_link_free()
After commit 1a80dbcb2dba, bpf_link can be freed by
link->ops->dealloc_deferred, but the code still tests and uses
link->ops->dealloc afterward, which leads to a use-after-free as
reported by syzbot. Actually, one of them should be sufficient, so
just call one of them instead of both. Also add a WARN_ON() in case
of any problematic implementation.33dCVE-2026-22878—19.9%
——6——CVE-2026-54768—19.9%
——6WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.34d