Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,365
- High10,105
- Medium4,998
- Low469
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-52340—15.0%
——5——CVE-2024-499847.8 HIG15.0%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/v3d: Prevent out of bounds access in performance query extensions
Check that the number of perfmons userspace is passing in the copy and
reset extensions is not greater than the internal kernel storage where
the ids will be copied into.23dCVE-2024-459336.6 MED15.0%
——4OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint.54dCVE-2026-25582—15.0%
——4——CVE-2022-39901—15.0%
——4——CVE-2024-32116—15.0%
——4——CVE-2025-60267—15.0%
——4——CVE-2025-14722—15.0%
——4——CVE-2021-25336—15.0%
——4——CVE-2025-44375.7 MED15.0%
——4There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this file is excessively large, it can cause the a high memory consumption leading applications to be killed due to out-of-memory. As a result a denial-of-service can be achieved, possibly disrupting other pods and services running in the same host.6dCVE-2026-176495.3 MED15.0%
——4IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.8dCVE-2026-655385.9 MED15.0%
——4Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.35dCVE-2024-44663—15.0%
——4——CVE-2025-60265—15.0%
——4——CVE-2025-680815.9 MED15.0%
——4Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.35dCVE-2026-96805.8 MED15.0%
——4Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.30dCVE-2025-0642—15.0%
——4——CVE-2026-218403.1 LOW15.0%
——4HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.43dCVE-2023-52754—15.0%
——4——CVE-2026-710775.3 MED15.0%
——4Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).3dCVE-2026-577625.9 MED15.0%
——4Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.56dCVE-2026-115815.9 MED15.0%
——4The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's session. A missing capability check in the Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13's post-duplication action additionally lets the Contributor publish the malicious form so an administrator renders it.58dCVE-2024-44630—15.0%
——4——CVE-2023-52894—15.0%
——4——CVE-2021-1108—15.0%
——4——CVE-2023-1711—15.0%
——4——CVE-2026-57656—15.0%
——4——CVE-2025-7554—15.0%
——4——CVE-2025-23315—15.0%
——4——CVE-2026-347635.3 MED15.0%
——4Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path directly into a regular expression when deriving the displayed directory path. If root contains regex metacharacters such as +, *, or ., the prefix stripping can fail and the generated directory listing may expose the full filesystem path in the HTML output. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.34dCVE-2023-34431—15.0%
——4——CVE-2024-51931—15.0%
——4——CVE-2023-52826—15.0%
——4——CVE-2026-43048—15.0%
——4——CVE-2023-25445—15.0%
——4——CVE-2024-44660—14.9%
——4——CVE-2025-43015—15.0%
——4——CVE-2026-5028—15.0%
——4——CVE-2025-65328—15.0%
——4——CVE-2026-4515—15.0%
——4——