Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,389
- High10,127
- Medium5,026
- Low470
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-4023—14.7%
——4——CVE-2026-124977.5 HIG14.7%
——4The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some valid ways of configuring the offered roles the handler ignores the restriction and falls back to accepting any non-administrator role. Combined with the absence of a nonce on the public registration handler, this allows an unauthenticated visitor to register an account with a higher role, such as Editor or Author, than the form was configured to offer.34dCVE-2025-8208—14.7%
——4——CVE-2024-22028—14.7%
——4——CVE-2026-111708.1 HIG14.7%
——4Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)35dCVE-2024-37848—14.7%
——4——CVE-2026-5193—14.7%
——4——CVE-2026-47169—14.7%
——4——CVE-2025-64427—14.7%
——4——CVE-2025-25107—14.7%
——4——CVE-2025-57219—14.7%
——4——CVE-2023-32379—14.7%
——4——CVE-2024-43808—14.7%
——4——CVE-2025-12979—14.7%
——4——CVE-2022-3312—14.7%
——4——CVE-2025-47444—14.7%
——4——CVE-2024-20317—14.7%
——4——CVE-2025-55626—14.7%
——4——CVE-2025-10694—14.7%
——4——CVE-2022-48704—14.7%
——4——CVE-2025-12778—14.7%
——4——CVE-2022-48641—14.7%
——4——CVE-2021-47305—14.7%
——4——CVE-2024-394827.8 HIG14.7%
——4In the Linux kernel, the following vulnerability has been resolved:
bcache: fix variable length array abuse in btree_iter
btree_iter is used in two ways: either allocated on the stack with a
fixed size MAX_BSETS, or from a mempool with a dynamic size based on the
specific cache set. Previously, the struct had a fixed-length array of
size MAX_BSETS which was indexed out-of-bounds for the dynamically-sized
iterators, which causes UBSAN to complain.
This patch uses the same approach as in bcachefs's sort_iter and splits
the iterator into a btree_iter with a flexible array member and a
btree_iter_stack which embeds a btree_iter as well as a fixed-length
data array.23dCVE-2024-13724—14.7%
——4——CVE-2026-9199—14.7%
——4——CVE-2024-53228—14.7%
——4——CVE-2026-597634.3 MED14.7%
——4Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads1dCVE-2023-6998—14.7%
——4——CVE-2021-25514—14.7%
——4——CVE-2026-345115.3 MED14.7%
——4OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier, defeating PKCE protection and enabling token redemption.34dCVE-2024-30516—14.7%
——4——CVE-2025-31335—14.7%
——4——CVE-2024-42441—14.6%
——4——CVE-2025-26756—14.7%
——4——CVE-2025-3224—14.7%
——4——CVE-2026-40568—14.6%
——4——CVE-2026-6365—14.7%
——4——CVE-2022-4397—14.7%
——4——CVE-2025-55627—14.7%
——4——