Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,325
- High9,981
- Medium4,918
- Low460
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-27693—14.4%
——4——CVE-2024-13292—14.4%
——4——CVE-2022-22668—14.4%
——4——CVE-2026-6690—14.4%
——4——CVE-2024-39637—14.4%
——4——CVE-2024-43889—14.4%
——4——CVE-2025-57886—14.4%
——4——CVE-2022-50825—14.4%
——4——CVE-2026-0913—14.4%
——4——CVE-2026-325549.3 CRI14.4%
——4Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.2dCVE-2021-47456—14.4%
——4——CVE-2026-225547.8 HIG14.4%
——4MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability35dCVE-2022-48724—14.4%
——4——CVE-2026-25006—14.4%
——4——CVE-2025-56648—14.4%
——4——CVE-2025-1407—14.4%
——4——CVE-2025-61826—14.4%
——4——CVE-2024-438587.8 HIG14.4%
——4In the Linux kernel, the following vulnerability has been resolved:
jfs: Fix array-index-out-of-bounds in diFree23dCVE-2025-61836—14.4%
——4——CVE-2026-24037—14.4%
——4——CVE-2025-43226—14.4%
——4——CVE-2020-35567—14.4%
——4——CVE-2021-34864—14.4%
——4——CVE-2024-53187—14.4%
——4——CVE-2026-181444.3 MED14.4%
——4IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.10dCVE-2026-733889.3 CRI14.4%
——4Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.7dCVE-2021-47258—14.4%
——4——CVE-2021-47250—14.4%
——4——CVE-2023-6949—14.4%
——4——CVE-2026-325559.3 CRI14.4%
——4Unauthenticated SQL Injection in Boost <= 2.0.4 versions.2dCVE-2026-731839.3 CRI14.4%
——4Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.7dCVE-2026-161437.2 HIG14.4%
——4The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters such as double quotes), and in the editorder template which echoes the stored custmail value into an HTML input element's value attribute without esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.15dCVE-2026-457764.3 MED14.4%
——4OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafted HTTPS POST request that sets a session variable used for authorization decisions. If an installation of Open XDMoD includes the optional Job Performance (SUPReMM) module, an attacker could bypass intended data access restrictions and view other users' compute job efficiency metrics. All deployments of Open XDMoD prior to version 11.0.3 that contain the optional Job Performance (SUPReMM) module are impacted. This issue was reported privately on 2026-04-06, and at this time there is no evidence that this vulnerability has been exploited in the wild. The vulnerability was patched in Open XDMoD 11.0.3 on 2026-05-12. As a workaround, apply the patch manually.35dCVE-2023-40435—14.4%
——4——CVE-2026-0916—14.4%
——4——CVE-2021-47260—14.4%
——4——CVE-2025-48086—14.4%
——4——CVE-2025-35032—14.4%
——4——CVE-2026-325519.3 CRI14.4%
——4Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.3dCVE-2024-13388—14.4%
——4——