Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,311
- High9,414
- Medium5,381
- Low529
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-48610—18.0%
——5——CVE-2026-111539.1 CRI18.0%
——5Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)41dCVE-2020-0544—18.0%
——5——CVE-2026-563344.3 MED18.0%
——5Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and anonymous access from persisting builder status updates. Attackers can exploit this missing policy to cause build status and error details to remain unpersisted, leaving build_requests rows stuck in pending state with null last_error values.62dCVE-2025-710807.5 HIG18.0%
——5In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix a BUG in rt6_get_pcpu_route() under PREEMPT_RT
On PREEMPT_RT kernels, after rt6_get_pcpu_route() returns NULL, the
current task can be preempted. Another task running on the same CPU
may then execute rt6_make_pcpu_route() and successfully install a
pcpu_rt entry. When the first task resumes execution, its cmpxchg()
in rt6_make_pcpu_route() will fail because rt6i_pcpu is no longer
NULL, triggering the BUG_ON(prev). It's easy to reproduce it by adding
mdelay() after rt6_get_pcpu_route().
Using preempt_disable/enable is not appropriate here because
ip6_rt_pcpu_alloc() may sleep.
Fix this by handling the cmpxchg() failure gracefully on PREEMPT_RT:
free our allocation and return the existing pcpu_rt installed by
another task. The BUG_ON is replaced by WARN_ON_ONCE for non-PREEMPT_RT
kernels where such races should not occur.34dCVE-2026-1666—18.0%
——5——CVE-2023-49775—18.0%
——5——CVE-2025-32139—18.0%
——5——CVE-2022-49248—18.0%
——5——CVE-2025-67562—18.0%
——5——CVE-2026-25088—18.0%
——5——CVE-2024-5210—18.0%
——5——CVE-2026-68646.1 MED18.0%
——5The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link.40dCVE-2026-1634—18.0%
——5——CVE-2026-112427.5 HIG18.0%
——5Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)41dCVE-2020-24450—18.0%
——5——CVE-2026-631345.4 MED18.0%
——5Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathname))` that has no traversal protection. An uploaded malicious archive containing a directory entry with a `../` sequence or an absolute path causes the filebeat processing container to create directories outside the intended extraction directory. Version 26.07.0 fixes the issue.19dCVE-2023-47758—18.0%
——5——CVE-2025-6331410.0 CRI18.0%
——5A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.58dCVE-2026-468249.9 CRI18.0%
——5Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. While the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).42dCVE-2026-41233—18.0%
——5——CVE-2025-2685—18.0%
——5——CVE-2025-2982—18.0%
——5——CVE-2025-55736—18.0%
——5——CVE-2024-8996—18.0%
——5——CVE-2025-58156—18.0%
——5——CVE-2026-25123—18.0%
——5——CVE-2025-50062—18.0%
——5——CVE-2024-6004—18.0%
——5——CVE-2020-8678—18.0%
——5——CVE-2023-5893—18.0%
——5——CVE-2025-53000—18.0%
——5——CVE-2024-12825—18.0%
——5——CVE-2023-29425—18.0%
——5——CVE-2024-13773—18.0%
——5——CVE-2023-28596—18.0%
——5——CVE-2023-47806—18.0%
——5——CVE-2017-3741—18.0%
——5——CVE-2023-48772—18.0%
——5——CVE-2020-24462—18.0%
——5——