Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,311
- High9,414
- Medium5,381
- Low529
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-4370—18.1%
——5——CVE-2024-422597.8 HIG18.1%
——5In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Fix Virtual Memory mapping boundaries calculation
Calculating the size of the mapped area as the lesser value
between the requested size and the actual size does not consider
the partial mapping offset. This can cause page fault access.
Fix the calculation of the starting and ending addresses, the
total size is now deduced from the difference between the end and
start addresses.
Additionally, the calculations have been rewritten in a clearer
and more understandable form.
[Joonas: Add Requires: tag]
Requires: 60a2066c5005 ("drm/i915/gem: Adjust vma offset for framebuffer mmap offset")
(cherry picked from commit 97b6784753da06d9d40232328efc5c5367e53417)28dCVE-2025-24115—18.1%
——5——CVE-2025-58029—18.1%
——5——CVE-2025-403017.6 HIG18.1%
——5In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: validate skb length for unknown CC opcode
In hci_cmd_complete_evt(), if the command complete event has an unknown
opcode, we assume the first byte of the remaining skb->data contains the
return status. However, parameter data has previously been pulled in
hci_event_func(), which may leave the skb empty. If so, using skb->data[0]
for the return status uses un-init memory.
The fix is to check skb->len before using skb->data.34dCVE-2019-11288—18.1%
——5——CVE-2026-111139.6 CRI18.1%
——5Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)41dCVE-2025-65499—18.1%
——5——CVE-2025-11433—18.1%
——5——CVE-2026-742436.5 MED18.1%
——5A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths. The primary consequence is worker resource exhaustion and blind path manipulation on the configured Clair host, potentially leading to a denial of service.12dCVE-2026-181097.2 HIG18.1%
——5The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step.18dCVE-2026-33875—18.1%
——5——CVE-2025-58919—18.1%
——5——CVE-2026-31956—18.1%
——5——CVE-2026-600653.7 LOW18.1%
——5When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart.
Impact:
This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.22dCVE-2025-20241—18.1%
——5——CVE-2025-6550—18.1%
——5——CVE-2024-41176—18.1%
——5——CVE-2025-53756—18.1%
——5——CVE-2026-790756.5 MED18.1%
——5Information leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2025-6100—18.1%
——5——CVE-2022-28190—18.1%
——5——CVE-2022-49119—18.1%
——5——CVE-2025-65498—18.1%
——5——CVE-2024-52354—18.1%
——5——CVE-2024-24764—18.1%
——5——CVE-2024-52358—18.1%
——5——CVE-2025-12812—18.1%
——5——CVE-2025-65497—18.1%
——5——CVE-2025-63714—18.1%
——5——CVE-2026-46547—18.1%
——5——CVE-2026-217527.5 HIG18.1%
——5HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.4dCVE-2025-65496—18.1%
——5——CVE-2026-168254.2 MED18.1%
——5IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds write.8dCVE-2024-45314—18.1%
——5——CVE-2026-558856.8 MED18.1%
——5Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash and user/config with site configuration, through the backup download endpoint protected only by the session-static admin-nonce URL parameter. This issue is reported as fixed in version 1.7.53.50dCVE-2023-37246—18.1%
——5——CVE-2025-49562—18.1%
——5——CVE-2024-44254—18.1%
——5——CVE-2025-33015—18.1%
——5——