Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,360
- High9,604
- Medium5,457
- Low531
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-22745—15.6%
——5——CVE-2026-4516—15.6%
——5——CVE-2025-49318—15.6%
——5——CVE-2024-49820—15.6%
——5——CVE-2025-30630—15.6%
——5——CVE-2025-30320—15.6%
——5——CVE-2026-712347.5 HIG15.6%
——5Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0), without comparing it to any server-stored value.3dCVE-2022-4090—15.6%
——5——CVE-2025-66431—15.6%
——5——CVE-2025-60151—15.6%
——5——CVE-2025-68026—15.6%
——5——CVE-2026-7929—15.6%
——5——CVE-2022-48977—15.6%
——5——CVE-2026-32704—15.6%
——5——CVE-2018-6402—15.6%
——5——CVE-2025-12741—15.6%
——5——CVE-2024-37293—15.6%
——5——CVE-2021-22744—15.6%
——5——CVE-2022-49028—15.6%
——5——CVE-2021-22742—15.6%
——5——CVE-2025-31326—15.6%
——5——CVE-2024-26710—15.6%
——5——CVE-2026-786827.5 HIG15.6%
——5NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an internal loopback-only service, allowing disclosure of internal HTTP resources, loading of forged downloader indexes, and installation of attacker-chosen package content.14hCVE-2025-68024—15.6%
——5——CVE-2026-653415.4 MED15.6%
——5The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.11dCVE-2026-133455.3 MED15.6%
——5The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are otherwise withheld from public view.30dCVE-2026-99248.3 HIG15.6%
——5Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)39dCVE-2022-48975—15.6%
——5——CVE-2026-2505—15.6%
——5——CVE-2018-11258—15.6%
——5——CVE-2025-68542—15.6%
——5——CVE-2026-12316—15.6%
——5——CVE-2024-501158.4 HIG15.6%
——5In the Linux kernel, the following vulnerability has been resolved:
KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory
Ignore nCR3[4:0] when loading PDPTEs from memory for nested SVM, as bits
4:0 of CR3 are ignored when PAE paging is used, and thus VMRUN doesn't
enforce 32-byte alignment of nCR3.
In the absolute worst case scenario, failure to ignore bits 4:0 can result
in an out-of-bounds read, e.g. if the target page is at the end of a
memslot, and the VMM isn't using guard pages.
Per the APM:
The CR3 register points to the base address of the page-directory-pointer
table. The page-directory-pointer table is aligned on a 32-byte boundary,
with the low 5 address bits 4:0 assumed to be 0.
And the SDM's much more explicit:
4:0 Ignored
Note, KVM gets this right when loading PDPTRs, it's only the nSVM flow
that is broken.25dCVE-2025-49322—15.6%
——5——CVE-2023-54053—15.6%
——5——CVE-2026-42521—15.6%
——5——CVE-2022-48953—15.6%
——5——CVE-2025-30625—15.6%
——5——CVE-2026-725847.4 HIG15.6%
——5A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attacker to bypass the OTP attempt limit on the account recovery flow, enabling brute-force attacks on 6-digit OTP codes.15hCVE-2025-13177—15.6%
——5——