Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-25264—15.3%
——5——CVE-2022-27635—15.3%
——5——CVE-2023-37992—15.3%
——5——CVE-2023-52619—15.3%
——5——CVE-2021-479226.4 MED15.3%
——5Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScript payloads in the title field when creating or editing sliders, which executes in the browsers of users viewing the slider on both administrative and frontend pages.34dCVE-2025-36896—15.3%
——5——CVE-2024-531107.3 HIG15.3%
——5In the Linux kernel, the following vulnerability has been resolved:
vp_vdpa: fix id_table array not null terminated error
Allocate one extra virtio_device_id as null terminator, otherwise
vdpa_mgmtdev_get_classes() may iterate multiple times and visit
undefined memory.24dCVE-2023-52475—15.3%
——5——CVE-2025-30455—15.3%
——5——CVE-2023-35136—15.3%
——5——CVE-2026-1889—15.3%
——5——CVE-2026-116719.6 CRI15.3%
——5Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)36dCVE-2024-56600—15.3%
——5——CVE-2026-153346.4 MED15.3%
——5The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon.view' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.34dCVE-2026-27917—15.3%
——5——CVE-2021-47962—15.3%
——5——CVE-2026-3527—15.3%
——5——CVE-2026-54319—15.3%
——5——CVE-2025-68591—15.3%
——5——CVE-2025-36904—15.3%
——5——CVE-2025-52043—15.3%
——5——CVE-2025-50949—15.3%
——5——CVE-2025-12834—15.3%
——5——CVE-2026-26166—15.3%
——5——CVE-2026-624307.5 HIG15.3%
——5Accesses to the CMOS memory contents are done using an indirect IO port
pair. Therefore Xen needs to cache the guest chosen index, and one of
the usages of the index didn't take the necessary locking to avoid
concurrent changes. As a result, a guest could change the index after
it being checked, causing a subsequent out-of-bound read access to the
contents of an array.30dCVE-2024-567207.8 HIG15.3%
——5In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Several fixes to bpf_msg_pop_data
Several fixes to bpf_msg_pop_data,
1. In sk_msg_shift_left, we should put_page
2. if (len == 0), return early is better
3. pop the entire sk_msg (last == msg->sg.size) should be supported
4. Fix for the value of variable "a"
5. In sk_msg_shift_left, after shifting, i has already pointed to the next
element. Addtional sk_msg_iter_var_next may result in BUG.24dCVE-2020-37225—15.3%
——5——CVE-2026-39417—15.3%
——5——CVE-2025-1472—15.3%
——5——CVE-2026-32195—15.3%
——5——CVE-2025-13988—15.3%
——5——CVE-2025-49570—15.3%
——5——CVE-2026-1093—15.3%
——5——CVE-2025-15112—15.3%
——5——CVE-2024-41068—15.3%
——5——CVE-2025-8176—15.3%
——5——CVE-2022-29615—15.3%
——5——CVE-2025-26703—15.3%
——5——CVE-2017-18157—15.3%
——5——CVE-2026-5774—15.3%
——5——