Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-436347.5 HIG15.0%
——5HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated from Cloudflare's network. Attackers can exploit this to circumvent fail2ban brute-force protection, bypass per-user IP allowlists, and poison authentication audit logs by spoofing trusted IP addresses on each request.35dCVE-2023-2895—15.0%
——5——CVE-2024-13547—15.0%
——5——CVE-2022-20273—15.0%
——5——CVE-2023-2893—15.0%
——5——CVE-2023-32076—15.0%
——5——CVE-2023-2894—15.0%
——5——CVE-2026-165977.2 HIG15.0%
——5The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the GTM4WP WooCommerce order data integration option (GTM4WP_OPTION_INTEGRATE_WCORDERDATA) to be enabled, and is exploited by placing a guest checkout order with a JavaScript payload in a WooCommerce billing field such as the billing first name.28dCVE-2021-47171—15.0%
——5——CVE-2024-392927.8 HIG15.0%
——5In the Linux kernel, the following vulnerability has been resolved:
um: Add winch to winch_handlers before registering winch IRQ
Registering a winch IRQ is racy, an interrupt may occur before the winch is
added to the winch_handlers list.
If that happens, register_winch_irq() adds to that list a winch that is
scheduled to be (or has already been) freed, causing a panic later in
winch_cleanup().
Avoid the race by adding the winch to the winch_handlers list before
registering the IRQ, and rolling back if um_request_irq() fails.24dCVE-2024-32438—15.0%
——5——CVE-2023-3408—15.0%
——5——CVE-2023-39458—15.0%
——5——CVE-2023-2896—15.0%
——5——CVE-2025-43298—15.0%
——5——CVE-2026-15315—15.0%
——5Tapo C200 v5
contains an improper authentication vulnerability within the login
authentication verification module. An attacker on the local network can
exploit weaknesses in challenge parameter validation to bypass normal
authentication controls and obtain administrative session tokens.
Successful
exploitation may allow an attacker to subsequently execute privileged
management actions, enable unauthorized administrative access and temporary
disruption of device services, resulting in a denial-of-service (DoS)
condition.7dCVE-2026-7148—15.0%
——5——CVE-2024-23510—15.0%
——5——CVE-2024-49933—15.0%
——5——CVE-2021-33101—15.0%
——5——CVE-2023-52999—15.0%
——5——CVE-2025-24277—15.0%
——5——CVE-2026-112488.8 HIG15.0%
——5Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)36dCVE-2024-32439—15.0%
——5——CVE-2026-27818—15.0%
——5——CVE-2025-9822—15.0%
——5——CVE-2024-13644—15.0%
——5——CVE-2024-53386—15.0%
——5——CVE-2024-44990—15.0%
——5——CVE-2024-9496—15.0%
——5——CVE-2026-18328—15.0%
——5——CVE-2026-289817.8 HIG15.0%
——5A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.30dCVE-2025-25683—15.0%
——5——CVE-2024-38543—15.0%
——5——CVE-2025-43408—15.0%
——5——CVE-2023-51528—15.0%
——5——CVE-2025-62469—15.0%
——5——CVE-2025-13535—15.0%
——5——CVE-2024-32440—15.0%
——5——CVE-2026-7742—15.0%
——5——