Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,325
- High9,981
- Medium4,918
- Low460
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-31068—14.5%
——4——CVE-2020-12904—14.5%
——4——CVE-2025-48488—14.5%
——4——CVE-2025-257996.0 MED14.5%
——4SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.54dCVE-2025-53237—14.5%
——4——CVE-2026-22455—14.5%
——4——CVE-2026-733607.1 HIG14.5%
——4Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.7dCVE-2026-57283—14.5%
——4——CVE-2024-43904—14.5%
——4——CVE-2023-25508—14.5%
——4——CVE-2025-20141—14.5%
——4——CVE-2026-22491—14.5%
——4——CVE-2023-39187—14.5%
——4——CVE-2026-733937.1 HIG14.5%
——4Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.7dCVE-2026-728005.8 MED14.5%
——4SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally, getBlockDefIDsByRefText and getBlockRelevantIDs endpoints enumerate workspace-wide block IDs without publish scoping, enabling attackers to discover valid block identifiers across publish boundaries and access content from hidden or password-protected documents.22hCVE-2022-48701—14.5%
——4——CVE-2026-733587.1 HIG14.5%
——4Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.7dCVE-2026-106636.1 MED14.5%
——4In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_device slab object without clearing the cached pointer ctx->root. The bus removal handler dev_removed_handler() (subsys/usb/host/usbh_core.c) decides what to tear down solely from ctx->root, checking only that it is non-NULL.
Because UHC controller drivers (e.g. uhc_max3421e, uhc_mcux_common) synthesize UHC_EVT_DEV_REMOVED directly from physical bus line state with no debounce or state guard, an attacker with physical USB access (or a rogue device that bounces its connection) can deliver a second device-removed event after a root device disconnect. The handler then re-enters usbh_device_disconnect() with the dangling pointer, locking a mutex inside the freed object (use-after-free), removing the freed node from the device list, and calling k_mem_slab_free() on the already-freed block (double-free). If the slab block has been reissued to a newly attached device in between, this corrupts a live object.
Impact is denial of service (crash) and memory corruption; the attack vector is physical/local. The flaw was introduced in v4.4.0 by the connect/disconnect refactor and is fixed by clearing ctx->root in usbh_device_disconnect() before freeing.42dCVE-2011-1352—14.5%
——4——CVE-2024-274037.8 HIG14.5%
——4In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_flow_offload: reset dst in route object after setting up flow
dst is transferred to the flow object, route object does not own it
anymore. Reset dst in route object, otherwise if flow_offload_add()
fails, error path releases dst twice, leading to a refcount underflow.23dCVE-2025-24503—14.5%
——4——CVE-2025-6749—14.5%
——4——CVE-2026-120266.5 MED14.5%
——4Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)58dCVE-2026-25356—14.5%
——4——CVE-2025-11270—14.5%
——4——CVE-2025-48484—14.4%
——4——CVE-2026-66955.5 MED14.5%
——4A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.8dCVE-2026-65766—14.5%
——4Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.31dCVE-2025-6753—14.5%
——4——CVE-2024-53208—14.5%
——4——CVE-2023-39182—14.5%
——4——CVE-2026-27524—14.5%
——4——CVE-2020-35567—14.4%
——4——CVE-2024-438587.8 HIG14.4%
——4In the Linux kernel, the following vulnerability has been resolved:
jfs: Fix array-index-out-of-bounds in diFree23dCVE-2025-61836—14.4%
——4——CVE-2024-43889—14.4%
——4——CVE-2025-1407—14.4%
——4——CVE-2025-61826—14.4%
——4——CVE-2026-24037—14.4%
——4——CVE-2025-43226—14.4%
——4——