Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,394
- High10,137
- Medium5,050
- Low465
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-59016—13.6%
——4——CVE-2024-41344—13.6%
——4——CVE-2024-35936—13.6%
——4——CVE-2020-26893—13.6%
——4——CVE-2024-20347—13.6%
——4——CVE-2026-24902—13.6%
——4——CVE-2026-194062.7 LOW13.6%
——4The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.6dCVE-2025-68844—13.6%
——4——CVE-2022-50824—13.6%
——4——CVE-2022-50834—13.6%
——4——CVE-2024-47555—13.6%
——4——CVE-2025-48203—13.6%
——4——CVE-2025-21865—13.6%
——4——CVE-2024-42302—13.6%
——4——CVE-2022-22426—13.6%
——4——CVE-2025-463995.5 MED13.6%
——4A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.57dCVE-2021-26366—13.6%
——4——CVE-2021-29618—13.6%
——4——CVE-2022-50713—13.6%
——4——CVE-2024-35825—13.6%
——4——CVE-2025-62915—13.6%
——4——CVE-2023-43580—13.6%
——4——CVE-2025-464005.5 MED13.6%
——4In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.57dCVE-2025-69368—13.6%
——4——CVE-2021-32002—13.6%
——4——CVE-2025-14384—13.6%
——4——CVE-2023-43575—13.6%
——4——CVE-2026-116768.3 HIG13.6%
——4Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)33dCVE-2023-43571—13.6%
——4——CVE-2023-1990—13.6%
——4——CVE-2023-43581—13.6%
——4——CVE-2025-59560—13.6%
——4——CVE-2025-15258—13.6%
——4——CVE-2026-40765—13.6%
——4——CVE-2022-492037.8 HIG13.6%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix double free during GPU reset on DC streams
[Why]
The issue only occurs during the GPU reset code path.
We first backup the current state prior to commiting 0 streams
internally from DM to DC. This state backup contains valid link
encoder assignments.
DC will clear the link encoder assignments as part of current state
(but not the backup, since it was a copied before the commit) and
free the extra stream reference it held.
DC requires that the link encoder assignments remain cleared/invalid
prior to commiting. Since the backup still has valid assignments we
call the interface post reset to clear them. This routine also
releases the extra reference that the link encoder interface held -
resulting in a double free (and eventually a NULL pointer dereference).
[How]
We'll have to do a full DC commit anyway after GPU reset because
the stream count previously went to 0.
We don't need to retain the assignment that we had backed up, so
just copy off of the now clean current state assignment after the
reset has occcurred with the new link_enc_cfg_copy() interface.21dCVE-2025-43423—13.6%
——4——CVE-2025-68856—13.6%
——4——CVE-2026-216609.8 CRI13.6%
——4A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise
This issue affects Frick Controls Quantum HD version 10.22 and prior.1dCVE-2023-43569—13.6%
——4——CVE-2023-30739—13.6%
——4——