Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-47065—15.1%
——5——CVE-2024-39866—15.1%
——5——CVE-2019-25398—15.1%
——5——CVE-2023-48267—15.1%
——5——CVE-2025-43196—15.1%
——5——CVE-2023-28804—15.1%
——5——CVE-2017-18274—15.1%
——5——CVE-2026-484465.5 MED15.1%
——5CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.13dCVE-2023-36307—15.1%
——5——CVE-2024-40832—15.1%
——5——CVE-2025-292676.5 MED15.1%
——5SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to obtain a sensitive information via the cid parameter in the GET request.53dCVE-2026-116618.3 HIG15.1%
——5Use after free in Views in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)36dCVE-2021-0245—15.1%
——5——CVE-2024-52357—15.1%
——5——CVE-2022-47505—15.1%
——5——CVE-2025-45702—15.1%
——5——CVE-2024-29645—15.1%
——5——CVE-2025-49981—15.1%
——5——CVE-2020-9105—15.1%
——5——CVE-2024-4754—15.1%
——5——CVE-2026-7824—15.1%
——5——CVE-2024-6361—15.1%
——5——CVE-2025-24450—15.1%
——5——CVE-2026-15283—15.1%
——5——CVE-2023-29497—15.1%
——5——CVE-2025-68994—15.1%
——5——CVE-2026-26271—15.1%
——5——CVE-2023-53938—15.1%
——5——CVE-2025-30296—15.1%
——5——CVE-2024-531067.3 HIG15.1%
——5In the Linux kernel, the following vulnerability has been resolved:
ima: fix buffer overrun in ima_eventdigest_init_common
Function ima_eventdigest_init() calls ima_eventdigest_init_common()
with HASH_ALGO__LAST which is then used to access the array
hash_digest_size[] leading to buffer overrun. Have a conditional
statement to handle this.24dCVE-2026-28994—15.1%
——5——CVE-2025-41718—15.1%
——5——CVE-2022-47512—15.1%
——5——CVE-2022-25338—15.1%
——5——CVE-2024-54473—15.1%
——5——CVE-2020-36777—15.1%
——5——CVE-2026-43249—15.1%
——5——CVE-2024-32902—15.1%
——5——CVE-2026-160806.5 MED15.1%
——5The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.8dCVE-2026-35624—15.1%
——5——