Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,394
- High10,137
- Medium5,050
- Low465
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-11820—13.7%
——4——CVE-2025-0116—13.7%
——4——CVE-2021-20075—13.7%
——4——CVE-2026-63747.3 HIG13.7%
——4Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable.
This issue affects WAH7601: through 20.07.2026.15dCVE-2024-56257—13.7%
——4——CVE-2025-1754—13.7%
——4——CVE-2023-30997—13.7%
——4——CVE-2024-38637—13.7%
——4——CVE-2025-31703—13.7%
——4——CVE-2023-21454—13.7%
——4——CVE-2026-178186.1 MED13.7%
——4Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)22dCVE-2026-6764—13.7%
——4——CVE-2026-7578—13.7%
——4——CVE-2021-0109—13.7%
——4——CVE-2025-62327—13.7%
——4——CVE-2026-28424—13.7%
——4——CVE-2024-42796—13.7%
——4——CVE-2024-11029—13.7%
——4——CVE-2020-36880—13.7%
——4——CVE-2026-393914.8 MED13.7%
——4CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the blacklist (ban) note parameter in UserController::ajax_blackList_post() is stored in the database without sanitization and rendered into an HTML data-note attribute without escaping. An admin with blacklist privileges can inject arbitrary JavaScript that executes in the browser of any other admin who views the user management page. This vulnerability is fixed in 0.31.4.0.36dCVE-2021-471537.8 HIG13.7%
——4In the Linux kernel, the following vulnerability has been resolved:
i2c: i801: Don't generate an interrupt on bus reset
Now that the i2c-i801 driver supports interrupts, setting the KILL bit
in a attempt to recover from a timed out transaction triggers an
interrupt. Unfortunately, the interrupt handler (i801_isr) is not
prepared for this situation and will try to process the interrupt as
if it was signaling the end of a successful transaction. In the case
of a block transaction, this can result in an out-of-range memory
access.
This condition was reproduced several times by syzbot:
https://syzkaller.appspot.com/bug?extid=ed71512d469895b5b34e
https://syzkaller.appspot.com/bug?extid=8c8dedc0ba9e03f6c79e
https://syzkaller.appspot.com/bug?extid=c8ff0b6d6c73d81b610e
https://syzkaller.appspot.com/bug?extid=33f6c360821c399d69eb
https://syzkaller.appspot.com/bug?extid=be15dc0b1933f04b043a
https://syzkaller.appspot.com/bug?extid=b4d3fd1dfd53e90afd79
So disable interrupts while trying to reset the bus. Interrupts will
be enabled again for the following transaction.21dCVE-2022-35631—13.7%
——4——CVE-2026-706178.1 HIG13.7%
——4Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete message history, post messages as a participant, and force-add third-party users without their consent.19dCVE-2025-220877.8 HIG13.7%
——4In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix array bounds error with may_goto
may_goto uses an additional 8 bytes on the stack, which causes the
interpreters[] array to go out of bounds when calculating index by
stack_size.
1. If a BPF program is rewritten, re-evaluate the stack size. For non-JIT
cases, reject loading directly.
2. For non-JIT cases, calculating interpreters[idx] may still cause
out-of-bounds array access, and just warn about it.
3. For jit_requested cases, the execution of bpf_func also needs to be
warned. So move the definition of function __bpf_prog_ret0_warn out of
the macro definition CONFIG_BPF_JIT_ALWAYS_ON.27dCVE-2024-52935—13.7%
——4——CVE-2025-12449—13.7%
——4——CVE-2026-179414.3 MED13.7%
——4Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)22dCVE-2024-55459—13.7%
——4——CVE-2026-608026.1 MED13.7%
——4Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle E-Business Intelligence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Intelligence accessible data as well as unauthorized read access to a subset of Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).22dCVE-2024-50051—13.7%
——4——CVE-2025-55810—13.7%
——4——CVE-2026-169596.8 MED13.7%
——4The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.4dCVE-2024-22155—13.7%
——4——CVE-2026-41232—13.7%
——4——CVE-2026-33395—13.7%
——4——CVE-2023-30998—13.7%
——4——CVE-2026-0154—13.7%
——4——CVE-2026-25768—13.7%
——4——CVE-2026-599508.1 HIG13.7%
——4The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.39dCVE-2025-31362—13.7%
——4——