Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,370
- High10,112
- Medium5,014
- Low469
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-136098.8 HIG14.8%
——4The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9's front-end display surfaces, resulting in stored cross-site scripting that executes in the browser of any user, including an administrator, who views a page displaying the submitted value.1dCVE-2024-33489—14.8%
——4——CVE-2017-18159—14.8%
——4——CVE-2023-54057—14.8%
——4——CVE-2022-487427.8 HIG14.8%
——4In the Linux kernel, the following vulnerability has been resolved:
rtnetlink: make sure to refresh master_dev/m_ops in __rtnl_newlink()
While looking at one unrelated syzbot bug, I found the replay logic
in __rtnl_newlink() to potentially trigger use-after-free.
It is better to clear master_dev and m_ops inside the loop,
in case we have to replay it.23dCVE-2022-47637—14.8%
——4——CVE-2020-10697—14.8%
——4——CVE-2023-53887—14.8%
——4——CVE-2025-6255—14.8%
——4——CVE-2025-20189—14.8%
——4——CVE-2026-725628.8 HIG14.8%
——4An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can exfiltrate or modify all database contents.16dCVE-2023-54158—14.8%
——4——CVE-2026-24890—14.8%
——4——CVE-2023-53897—14.8%
——4——CVE-2025-21776—14.8%
——4——CVE-2025-11238—14.8%
——4——CVE-2024-5768—14.8%
——4——CVE-2025-62358—14.8%
——4——CVE-2023-53932—14.8%
——4——CVE-2026-5113—14.8%
——4——CVE-2023-52896—14.8%
——4——CVE-2025-57982—14.8%
——4——CVE-2025-49412—14.8%
——4——CVE-2019-25284—14.8%
——4——CVE-2024-44963—14.8%
——4——CVE-2024-34085—14.8%
——4——CVE-2025-9493—14.8%
——4——CVE-2025-9126—14.8%
——4——CVE-2025-9442—14.8%
——4——CVE-2025-10181—14.8%
——4——CVE-2023-52507—14.8%
——4——CVE-2025-8073—14.8%
——4——CVE-2025-68118—14.8%
——4——CVE-2019-25263—14.8%
——4——CVE-2026-32721—14.8%
——4——CVE-2022-50670—14.8%
——4——CVE-2024-45008—14.8%
——4——CVE-2022-50672—14.8%
——4——CVE-2025-66574—14.8%
——4——CVE-2025-9849—14.8%
——4——