Vulnerabilities exploitable today
367,165in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,273
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2015-5960—17.3%
——5——CVE-2026-99408.8 HIG17.3%
——5Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)41dCVE-2021-43751—17.3%
——5——CVE-2026-440948.6 HIG17.3%
——5An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.32dCVE-2013-5193—17.3%
——5——CVE-2022-43295—17.3%
——5——CVE-2025-31365—17.3%
——5——CVE-2026-42070—17.3%
——5——CVE-2018-11882—17.3%
——5——CVE-2024-9582—17.3%
——5——CVE-2024-47713—17.3%
——5——CVE-2022-385837.8 HIG17.3%
——5On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 workstation user could abuse their access to the "SharedData" folder on the connected Sage 300 server to view and/or modify the credentials associated with Sage 300 users and SQL accounts to impersonate users and/or access the SQL database as a system administrator. With system administrator-level access to the Sage 300 MS SQL database it would be possible to create, update, and delete all records associated with the program and, depending on the configuration, execute code on the underlying database server.54dCVE-2021-4446—17.3%
——5——CVE-2026-37007—17.3%
——5A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.4dCVE-2023-41996—17.3%
——5——CVE-2026-2709—17.3%
——5——CVE-2026-179409.6 CRI17.3%
——5Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)28dCVE-2026-22033—17.3%
——5——CVE-2023-41743—17.3%
——5——CVE-2025-67787—17.3%
——5——CVE-2026-7321—17.3%
——5——CVE-2026-54217—17.3%
——5Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An
attacker can send an email containing malicious JavaScript code. When a
user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.5dCVE-2026-42909.1 CRI17.3%
——5The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete() method passing the user ID directly to wp_delete_user() without any role validation. This makes it possible for unauthenticated attackers to delete arbitrary user accounts, including those of administrators.41dCVE-2026-30711—17.3%
——5——CVE-2025-6982—17.3%
——5——CVE-2024-2010—17.3%
——5——CVE-2026-714685.3 MED17.3%
——5A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.4dCVE-2026-32734—17.3%
——5——CVE-2024-385837.8 HIG17.3%
——5In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix use-after-free of timer for log writer thread
Patch series "nilfs2: fix log writer related issues".
This bug fix series covers three nilfs2 log writer-related issues,
including a timer use-after-free issue and potential deadlock issue on
unmount, and a potential freeze issue in event synchronization found
during their analysis. Details are described in each commit log.
This patch (of 3):
A use-after-free issue has been reported regarding the timer sc_timer on
the nilfs_sc_info structure.
The problem is that even though it is used to wake up a sleeping log
writer thread, sc_timer is not shut down until the nilfs_sc_info structure
is about to be freed, and is used regardless of the thread's lifetime.
Fix this issue by limiting the use of sc_timer only while the log writer
thread is alive.27dCVE-2025-26947—17.3%
——5——CVE-2025-12732—17.3%
——5——CVE-2026-467395.3 MED17.3%
——5Net::Statsd versions before 0.13 for Perl allow metric injections.
The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
The update_stats (used for updating counters) and gauge methods do not check that values are numeric (which would block metric injection).40dCVE-2026-1298—17.3%
——5——CVE-2023-53863—17.3%
——5——CVE-2024-548556.4 MED17.3%
——5fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.57dCVE-2025-25958—17.3%
——5——CVE-2025-64299—17.3%
——5——CVE-2024-34561—17.3%
——5——CVE-2025-22268—17.3%
——5——CVE-2024-531657.4 HIG17.3%
——5In the Linux kernel, the following vulnerability has been resolved:
sh: intc: Fix use-after-free bug in register_intc_controller()
In the error handling for this function, d is freed without ever
removing it from intc_list which would lead to a use after free.
To fix this, let's only add it to the list after everything has
succeeded.27d