Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,296
- High9,357
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-491265.5 MED16.5%
——5In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix memory leaks
Fix memory leaks related to operational reply queue's memory segments which
are not getting freed while unloading the driver.17dCVE-2026-93766.3 MED16.5%
——5A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCenter Article Submission Endpoint. Executing a manipulation of the argument id/userId can lead to improper authorization. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.38dCVE-2026-10623—16.5%
——5——CVE-2024-12306—16.5%
——5——CVE-2026-139594.3 MED16.5%
——5Insufficient validation of untrusted input in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)58dCVE-2025-378457.8 HIG16.5%
——5In the Linux kernel, the following vulnerability has been resolved:
tracing: fprobe events: Fix possible UAF on modules
Commit ac91052f0ae5 ("tracing: tprobe-events: Fix leakage of module
refcount") moved try_module_get() from __find_tracepoint_module_cb()
to find_tracepoint() caller, but that introduced a possible UAF
because the module can be unloaded before try_module_get(). In this
case, the module object should be freed too. Thus, try_module_get()
does not only fail but may access to the freed object.
To avoid that, try_module_get() in __find_tracepoint_module_cb()
again.31dCVE-2026-2860—16.5%
——5——CVE-2025-63883—16.5%
——5——CVE-2025-40924—16.5%
——5——CVE-2024-47145—16.5%
——5——CVE-2024-9766—16.5%
——5——CVE-2025-68132—16.5%
——5——CVE-2021-24870—16.5%
——5——CVE-2026-75831—16.5%
——5——CVE-2024-39271—16.5%
——5——CVE-2026-501308.8 HIG16.5%
——5Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.30dCVE-2021-41562—16.5%
——5——CVE-2026-6979—16.5%
——5——CVE-2022-21508—16.5%
——5——CVE-2020-0132—16.5%
——5——CVE-2026-32123—16.5%
——5——CVE-2026-5779—16.5%
——5——CVE-2024-53871—16.5%
——5——CVE-2026-33503—16.5%
——5——CVE-2026-2274—16.5%
——5——CVE-2025-51569—16.5%
——5——CVE-2020-5324—16.5%
——5——CVE-2020-36998—16.5%
——5——CVE-2026-8951—16.5%
——5——CVE-2025-2350—16.4%
——5——CVE-2025-48240—16.4%
——5——CVE-2021-47315—16.4%
——5——CVE-2022-42314—16.4%
——5——CVE-2025-47443—16.4%
——5——CVE-2026-39335—16.4%
——5——CVE-2018-7991—16.4%
——5——CVE-2022-42318—16.4%
——5——CVE-2025-48118—16.4%
——5——CVE-2026-31513—16.4%
——5——CVE-2025-60869—16.4%
——5——