Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-69242—15.0%
——5——CVE-2024-26767—15.0%
——5——CVE-2021-47557—15.0%
——5——CVE-2023-1552—15.0%
——5——CVE-2025-27633—15.0%
——5——CVE-2024-409867.8 HIG15.0%
——5In the Linux kernel, the following vulnerability has been resolved:
dmaengine: xilinx: xdma: Fix data synchronisation in xdma_channel_isr()
Requests the vchan lock before using xdma->stop_request.24dCVE-2024-30482—15.0%
——5——CVE-2026-33729—15.0%
——5——CVE-2024-56558—15.0%
——5——CVE-2024-32442—15.0%
——5——CVE-2024-54010—15.0%
——5——CVE-2024-409917.8 HIG15.0%
——5In the Linux kernel, the following vulnerability has been resolved:
dmaengine: ti: k3-udma-glue: Fix of_k3_udma_glue_parse_chn_by_id()
The of_k3_udma_glue_parse_chn_by_id() helper function erroneously
invokes "of_node_put()" on the "udmax_np" device-node passed to it,
without having incremented its reference count at any point. Fix it.24dCVE-2024-13456—15.0%
——5——CVE-2025-4439—15.0%
——5——CVE-2023-2680—15.0%
——5——CVE-2024-30457—15.0%
——5——CVE-2026-725746.1 MED15.0%
——5A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control the origin of JavaScript and CSS assets loaded by the default theme. When base_url is unset (the default), Pico::getBaseUrl in lib/Pico.php builds the base URL from unvalidated Host, X-Forwarded-Host, X-Forwarded-Proto, and X-Forwarded-Port request headers.17dCVE-2024-11780—15.0%
——5——CVE-2023-4949—15.0%
——5——CVE-2021-23843—15.0%
——5——CVE-2026-399645.4 MED15.0%
——5TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble content without filtering the javascript: URI scheme. A bot author can set a link URL to javascript:PAYLOAD, which executes in the visitor's browser context when clicked. Since the viewer is typically embedded in a third-party site, the attacker's JavaScript runs in the host page's origin and can exfiltrate cookies and session tokens. This can result in any authenticated Typebot user (including those on the free tier) being able to create a bot with this payload. Shared bots are publicly accessible — no victim authentication is required. This issue has been resolved in version 3.16.0.35dCVE-2026-7743—15.0%
——5——CVE-2021-23152—15.0%
——5——CVE-2024-9497—15.0%
——5——CVE-2023-51696—15.0%
——5——CVE-2024-12045—15.0%
——5——CVE-2024-32441—15.0%
——5——CVE-2024-42171—15.0%
——5——CVE-2024-13701—15.0%
——5——CVE-2021-46915—15.0%
——5——CVE-2024-359547.8 HIG15.0%
——5In the Linux kernel, the following vulnerability has been resolved:
scsi: sg: Avoid sg device teardown race
sg_remove_sfp_usercontext() must not use sg_device_destroy() after calling
scsi_device_put().
sg_device_destroy() is accessing the parent scsi_device request_queue which
will already be set to NULL when the preceding call to scsi_device_put()
removed the last reference to the parent scsi_device.
The resulting NULL pointer exception will then crash the kernel.24dCVE-2023-51529—15.0%
——5——CVE-2024-422367.8 HIG15.0%
——5In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()
Userspace provided string 's' could trivially have the length zero. Left
unchecked this will firstly result in an OOB read in the form
`if (str[0 - 1] == '\n') followed closely by an OOB write in the form
`str[0 - 1] = '\0'`.
There is already a validating check to catch strings that are too long.
Let's supply an additional check for invalid strings that are too short.24dCVE-2025-63386—15.0%
——5——CVE-2026-6982—15.0%
——5——CVE-2021-47171—15.0%
——5——CVE-2026-165977.2 HIG15.0%
——5The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the GTM4WP WooCommerce order data integration option (GTM4WP_OPTION_INTEGRATE_WCORDERDATA) to be enabled, and is exploited by placing a guest checkout order with a JavaScript payload in a WooCommerce billing field such as the billing first name.28dCVE-2024-392927.8 HIG15.0%
——5In the Linux kernel, the following vulnerability has been resolved:
um: Add winch to winch_handlers before registering winch IRQ
Registering a winch IRQ is racy, an interrupt may occur before the winch is
added to the winch_handlers list.
If that happens, register_winch_irq() adds to that list a winch that is
scheduled to be (or has already been) freed, causing a panic later in
winch_cleanup().
Avoid the race by adding the winch to the winch_handlers list before
registering the IRQ, and rolling back if um_request_irq() fails.24dCVE-2020-8030—15.0%
——5——CVE-2024-42173—15.0%
——5——