Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,374
- High9,657
- Medium5,454
- Low526
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-43745—15.9%
——5——CVE-2026-567435.4 MED15.9%
——5Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.43dCVE-2019-15332—15.9%
——5——CVE-2025-0954—15.9%
——5——CVE-2024-26764—15.9%
——5——CVE-2023-39923—15.9%
——5——CVE-2024-47390—15.9%
——5——CVE-2025-1551—15.9%
——5——CVE-2025-15369—15.9%
——5——CVE-2024-47630—15.9%
——5——CVE-2020-7123—15.9%
——5——CVE-2024-47357—15.9%
——5——CVE-2021-40989—15.9%
——5——CVE-2026-44471—15.9%
——5——CVE-2024-10310—15.9%
——5——CVE-2024-40455—15.9%
——5——CVE-2024-47366—15.9%
——5——CVE-2026-792484.3 MED15.9%
——5Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)23hCVE-2026-134257.2 HIG15.9%
——5The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by unauthenticated attackers because Contact Form 7 accepts array-structured input for ordinary text fields (e.g., your-name[]) via the public REST API endpoint /wp-json/contact-form-7/v1/contact-forms/{id}/feedback, and the plugin stores submitted data using $wpdb INSERT with serialize() into a custom wp_cf7db table, bypassing WordPress save-time filtering via wp_insert_post/wp_kses.30dCVE-2026-790824.3 MED15.9%
——5Incorrect authorization in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-792014.3 MED15.9%
——5Improper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)23hCVE-2019-15339—15.9%
——5——CVE-2024-9074—15.9%
——5——CVE-2021-3036—15.9%
——5——CVE-2026-792124.3 MED15.9%
——5Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)23hCVE-2024-47385—15.9%
——5——CVE-2024-50048—15.9%
——5——CVE-2019-15337—15.9%
——5——CVE-2019-15336—15.9%
——5——CVE-2026-42585—15.9%
——5——CVE-2026-726727.7 HIG15.9%
——5The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts.22hCVE-2019-15387—15.9%
——5——CVE-2025-9203—15.9%
——5——CVE-2022-41294—15.9%
——5——CVE-2020-7306—15.9%
——5——CVE-2022-34471—15.9%
——5——CVE-2023-25411—15.9%
——5——CVE-2023-38381—15.9%
——5——CVE-2024-369147.8 HIG15.9%
——5In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Skip on writeback when it's not applicable
[WHY]
dynamic memory safety error detector (KASAN) catches and generates error
messages "BUG: KASAN: slab-out-of-bounds" as writeback connector does not
support certain features which are not initialized.
[HOW]
Skip them when connector type is DRM_MODE_CONNECTOR_WRITEBACK.25dCVE-2023-7013—15.9%
——5——