Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,311
- High9,414
- Medium5,381
- Low529
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-27266—18.2%
——5——CVE-2023-37004—18.2%
——5——CVE-2026-30569—18.2%
——5——CVE-2025-20976—18.2%
——5——CVE-2025-51667—18.2%
——5——CVE-2026-792205.3 MED18.2%
——5Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)4dCVE-2026-159928.8 HIG18.2%
——5The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the attacker-supplied `role` parameter on any account resolved via `$_POST['user_login']`, without confirming the requesting user holds the capability to assign roles. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their own privileges to Administrator by submitting a crafted POST request — with `action` set to `createuser` and `role` set to `administrator` — to the password-reset form endpoint. The vulnerable code path is reachable via the `password_hint` filter hooked during the WordPress password-reset form render, meaning an attacker need only possess a valid password-reset cookie to reach the sink.34dCVE-2018-7946—18.2%
——5——CVE-2025-27306—18.2%
——5——CVE-2021-0176—18.2%
——5——CVE-2017-3226—18.2%
——5——CVE-2024-32634—18.2%
——5——CVE-2025-46720—18.2%
——5——CVE-2022-46422—18.2%
——5——CVE-2026-37100—18.2%
——5——CVE-2022-48424—18.2%
——5——CVE-2026-39377—18.2%
——5——CVE-2025-52784.4 MED18.2%
——5A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.12hCVE-2021-20536—18.2%
——5——CVE-2014-7573—18.2%
——5——CVE-2025-27280—18.2%
——5——CVE-2014-6844—18.2%
——5——CVE-2024-52366—18.2%
——5——CVE-2025-22479—18.2%
——5——CVE-2025-9658—18.2%
——5——CVE-2026-57923—18.2%
——5——CVE-2018-13014—18.2%
——5——CVE-2026-624428.1 HIG18.2%
——5Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).12dCVE-2023-31239—18.2%
——5——CVE-2026-132396.5 MED18.2%
——5Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from 0.0.0 to 4.2.0.26dCVE-2026-6347—18.2%
——5——CVE-2023-37012—18.2%
——5——CVE-2026-573756.5 MED18.2%
——5Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4.50dCVE-2026-30570—18.2%
——5——CVE-2025-27320—18.2%
——5——CVE-2024-7380—18.2%
——5——CVE-2024-21161—18.2%
——5——CVE-2025-27307—18.2%
——5——CVE-2024-24432—18.2%
——5——CVE-2023-37007—18.2%
——5——