Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,394
- High10,137
- Medium5,050
- Low465
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-0808—13.6%
——4——CVE-2025-69321—13.6%
——4——CVE-2026-6703—13.6%
——4——CVE-2025-6341—13.6%
——4——CVE-2021-36809—13.6%
——4——CVE-2016-0810—13.6%
——4——CVE-2026-9098—13.6%
——4——CVE-2025-68838—13.6%
——4——CVE-2025-5588—13.6%
——4——CVE-2025-32027—13.6%
——4——CVE-2023-29116—13.6%
——4——CVE-2022-35407—13.6%
——4——CVE-2024-35247—13.6%
——4——CVE-2020-9796—13.6%
——4——CVE-2021-28825—13.6%
——4——CVE-2025-5845—13.6%
——4——CVE-2025-68524—13.6%
——4——CVE-2026-2280—13.6%
——4——CVE-2023-52571—13.6%
——4——CVE-2025-2981—13.6%
——4——CVE-2025-68538—13.6%
——4——CVE-2025-44017—13.6%
——4——CVE-2026-40284—13.6%
——4——CVE-2021-34745—13.6%
——4——CVE-2025-64257—13.6%
——4——CVE-2025-29526—13.6%
——4——CVE-2025-37727—13.6%
——4——CVE-2025-2537—13.6%
——4——CVE-2024-30963—13.6%
——4——CVE-2026-167974.3 MED13.6%
——4The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary wp_options rows — including internal plugin news feed data, WooCommerce block pattern transients, and third-party configuration records — whose values are stored as arrays-of-arrays containing 'title' keys, enabling cross-plugin data leakage.28dCVE-2023-50975—13.6%
——4——CVE-2024-531277.8 HIG13.6%
——4In the Linux kernel, the following vulnerability has been resolved:
Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
The commit 8396c793ffdf ("mmc: dw_mmc: Fix IDMAC operation with pages
bigger than 4K") increased the max_req_size, even for 4K pages, causing
various issues:
- Panic booting the kernel/rootfs from an SD card on Rockchip RK3566
- Panic booting the kernel/rootfs from an SD card on StarFive JH7100
- "swiotlb buffer is full" and data corruption on StarFive JH7110
At this stage no fix have been found, so it's probably better to just
revert the change.
This reverts commit 8396c793ffdf28bb8aee7cfe0891080f8cab7890.21dCVE-2024-10090—13.6%
——4——CVE-2026-100067.5 HIG13.6%
——4Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)35dCVE-2026-25184.3 MED13.6%
——4The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing capability checks on the 'ultp_install_callback' and 'ultp_activate_callback' functions in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the PostX plugin.33dCVE-2024-40807—13.6%
——4——CVE-2026-174325.0 MED13.6%
——4A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is identified as 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3. Applying a patch is advised to resolve this issue.29dCVE-2021-47262—13.6%
——4——CVE-2026-39449—13.6%
——4——CVE-2026-192288.5 HIG13.6%
——4GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.6d