Vulnerabilities exploitable today
364,704in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,676
New KEV · 24H0
Exploit Today ≥ 701,621
Distribution · last window
- Critical2,341
- High10,013
- Medium4,922
- Low461
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-39708—14.1%
——4——CVE-2025-55133—14.1%
——4——CVE-2026-111728.8 HIG14.1%
——4Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)35dCVE-2023-51531—14.1%
——4——CVE-2026-111639.6 CRI14.1%
——4Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)35dCVE-2026-39574—14.1%
——4——CVE-2022-50741—14.1%
——4——CVE-2025-55134—14.1%
——4——CVE-2025-6693—14.1%
——4——CVE-2026-51714.3 MED14.1%
——4Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request.
This issue affects :
* Devolutions Server 2026.1.6.0 through 2026.1.16.0
* Devolutions Server 2025.3.20.0 and earlier35dCVE-2022-50766—14.1%
——4——CVE-2022-28792—14.1%
——4——CVE-2025-8580—14.1%
——4——CVE-2023-6055—14.1%
——4——CVE-2026-87916.4 MED14.1%
——4The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to a missing capability check on the `set_options` AJAX action when the plugin is operating in agency mode. The `trafftSetOptions()` handler verifies a nonce that is exposed to any authenticated user (it is printed inline on every admin page, including profile.php) but performs no capability check before calling `update_option('trafft_option', ['bookingWebsiteUrl' => ...])`. This setting is then used by `trafftAdminAssets()` to enqueue `<bookingWebsiteUrl>/embed.js` as a script on every front-end page that renders the booking shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to point the embed-script URL at an attacker-controlled origin and execute arbitrary JavaScript in the browser of every site visitor (including admins).28dCVE-2026-8519—14.1%
——4——CVE-2025-7849—14.1%
——4——CVE-2023-53837—14.1%
——4——CVE-2024-1162—14.1%
——4——CVE-2026-98749.6 CRI14.1%
——4Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)37dCVE-2026-5742—14.1%
——4——CVE-2024-32633—14.1%
——4——CVE-2026-111529.6 CRI14.1%
——4Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)35dCVE-2026-597138.1 HIG14.1%
——4Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victims in as the attacker.51dCVE-2022-50739—14.1%
——4——CVE-2025-54396—14.1%
——4——CVE-2026-782666.5 MED14.1%
——4Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.2dCVE-2026-8511—14.1%
——4——CVE-2024-420887.3 HIG14.1%
——4In the Linux kernel, the following vulnerability has been resolved:
ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link
Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component
and rework codec link") removed the codec entry for the ETDM1_OUT_BE
dai link entirely instead of replacing it with COMP_EMPTY(). This worked
by accident as the remaining COMP_EMPTY() platform entry became the codec
entry, and the platform entry became completely empty, effectively the
same as COMP_DUMMY() since snd_soc_fill_dummy_dai() doesn't do anything
for platform entries.
This causes a KASAN out-of-bounds warning in mtk_soundcard_common_probe()
in sound/soc/mediatek/common/mtk-soundcard-driver.c:
for_each_card_prelinks(card, i, dai_link) {
if (adsp_node && !strncmp(dai_link->name, "AFE_SOF", strlen("AFE_SOF")))
dai_link->platforms->of_node = adsp_node;
else if (!dai_link->platforms->name && !dai_link->platforms->of_node)
dai_link->platforms->of_node = platform_node;
}
where the code expects the platforms array to have space for at least one entry.
Add an COMP_EMPTY() entry so that dai_link->platforms has space.23dCVE-2025-60280—14.1%
——4——CVE-2023-52926—14.1%
——4——CVE-2025-50363—14.1%
——4——CVE-2024-56203—14.1%
——4——CVE-2026-321436.5 MED14.1%
——4Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, moderators could export CSV data for admin-restricted reports, bypassing the report visibility restrictions. This could expose sensitive operational data intended only for admins. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.34dCVE-2022-46720—14.1%
——4——CVE-2025-59408—14.1%
——4——CVE-2025-13980—14.1%
——4——CVE-2023-53830—14.1%
——4——CVE-2026-28782—14.1%
——4——CVE-2023-32401—14.1%
——4——