Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-55663—15.2%
——5——CVE-2026-5496—15.2%
——5——CVE-2026-179919.6 CRI15.2%
——5Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)24dCVE-2022-0192—15.2%
——5——CVE-2026-40148—15.2%
——5——CVE-2018-9381—15.2%
——5——CVE-2025-55647—15.2%
——5——CVE-2026-185107.2 HIG15.2%
——5The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation may delay exploitation for first-time commenters, but does not prevent it, as the payload uses only WordPress-permitted tags and attributes with percent-encoded characters that pass wp_kses URL validation unmodified.15dCVE-2022-50763—15.2%
——5——CVE-2025-609587.3 HIG15.2%
——5Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.53dCVE-2025-25526—15.2%
——5——CVE-2024-58110—15.2%
——5——CVE-2025-54981—15.2%
——5——CVE-2026-42439—15.2%
——5——CVE-2023-0832—15.2%
——5——CVE-2025-55650—15.2%
——5——CVE-2025-54754—15.2%
——5——CVE-2025-55643—15.2%
——5——CVE-2026-605798.0 HIG15.2%
——5Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).28dCVE-2022-50774—15.2%
——5——CVE-2026-398514.3 MED15.2%
——5Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.34dCVE-2026-563595.4 MED15.2%
——5n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authorization button, executing arbitrary scripts in their browser session with the victim's privileges.49dCVE-2021-28099—15.2%
——5——CVE-2025-20719—15.2%
——5——CVE-2025-42886—15.2%
——5——CVE-2026-56358—15.2%
——5——CVE-2026-98769.6 CRI15.2%
——5Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)38dCVE-2023-36748—15.2%
——5——CVE-2025-399439.4 CRI15.2%
——5In the Linux kernel, the following vulnerability has been resolved:
ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer
If data_offset and data_length of smb_direct_data_transfer struct are
invalid, out of bounds issue could happen.
This patch validate data_offset and data_length field in recv_done.29dCVE-2025-54733—15.2%
——5——CVE-2026-263796.5 MED15.2%
——5Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times.36dCVE-2024-8235—15.2%
——5——CVE-2021-0332—15.2%
——5——CVE-2024-468318.4 HIG15.2%
——5In the Linux kernel, the following vulnerability has been resolved:
net: microchip: vcap: Fix use-after-free error in kunit test
This is a clear use-after-free error. We remove it, and rely on checking
the return code of vcap_del_rule.24dCVE-2024-9198—15.2%
——5——CVE-2025-13849—15.2%
——5——CVE-2026-4269—15.2%
——5——CVE-2026-12465—15.2%
——5——CVE-2024-266977.8 HIG15.2%
——5In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix data corruption in dsync block recovery for small block sizes
The helper function nilfs_recovery_copy_block() of
nilfs_recovery_dsync_blocks(), which recovers data from logs created by
data sync writes during a mount after an unclean shutdown, incorrectly
calculates the on-page offset when copying repair data to the file's page
cache. In environments where the block size is smaller than the page
size, this flaw can cause data corruption and leak uninitialized memory
bytes during the recovery process.
Fix these issues by correcting this byte offset calculation on the page.24dCVE-2025-40915—15.2%
——5——