Vulnerabilities exploitable today
364,333in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,674
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,320
- High9,833
- Medium4,881
- Low459
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-48611—13.5%
——4——CVE-2026-43878—13.5%
——4——CVE-2024-24891—13.5%
——4——CVE-2026-33398—13.5%
——4NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only checks whether the caller is logged in, then reads a post by attacker-controlled `post` ID and returns its content. The backend helper in `modules/Forum/classes/Forum.php` does not enforce forum or topic ACLs. In contrast, the normal topic page in `modules/Forum/pages/forum/view_topic.php` enforces forum visibility and `view_other_topics`. Any low-privileged authenticated user can enumerate post IDs and read content from hidden, private, or staff-only forums. Version 2.2.5 fixes the issue.34dCVE-2026-2316—13.5%
——4——CVE-2026-57837.6 HIG13.5%
——4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus allows Reflected XSS.
This issue affects CityPLus: before V24.29750.1.0.32dCVE-2026-54329—13.5%
——4——CVE-2022-499917.8 HIG13.5%
——4In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: avoid corrupting page->mapping in hugetlb_mcopy_atomic_pte
In MCOPY_ATOMIC_CONTINUE case with a non-shared VMA, pages in the page
cache are installed in the ptes. But hugepage_add_new_anon_rmap is called
for them mistakenly because they're not vm_shared. This will corrupt the
page->mapping used by page cache code.20dCVE-2024-44661—13.5%
——4——CVE-2026-29134—13.5%
——4——CVE-2026-33477—13.5%
——4——CVE-2026-89936.5 MED13.5%
——4D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially crafted URL.33dCVE-2025-66910—13.5%
——4——CVE-2025-11815—13.5%
——4——CVE-2020-11308—13.5%
——4——CVE-2023-520708.4 HIG13.5%
——4JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.47dCVE-2025-63639—13.5%
——4——CVE-2024-5102—13.5%
——4——CVE-2026-110236.5 MED13.5%
——4Inappropriate implementation in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)33dCVE-2023-52568—13.5%
——4——CVE-2025-10902—13.5%
——4——CVE-2025-9129—13.5%
——4——CVE-2025-12961—13.5%
——4——CVE-2023-5165—13.5%
——4——CVE-2024-47238—13.5%
——4——CVE-2026-703989.6 CRI13.5%
——4A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects.10dCVE-2025-4172—13.5%
——4——CVE-2025-11176—13.5%
——4——CVE-2020-9084—13.5%
——4——CVE-2025-13393—13.5%
——4——CVE-2026-178136.5 MED13.5%
——4Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)21dCVE-2026-1307—13.5%
——4——CVE-2022-501677.8 HIG13.5%
——4In the Linux kernel, the following vulnerability has been resolved:
bpf: fix potential 32-bit overflow when accessing ARRAY map element
If BPF array map is bigger than 4GB, element pointer calculation can
overflow because both index and elem_size are u32. Fix this everywhere
by forcing 64-bit multiplication. Extract this formula into separate
small helper and use it consistently in various places.
Speculative-preventing formula utilizing index_mask trick is left as is,
but explicit u64 casts are added in both places.20dCVE-2026-179536.5 MED13.5%
——4Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)21dCVE-2026-32530—13.5%
——4——CVE-2026-6127—13.5%
——4——CVE-2025-4589—13.5%
——4——CVE-2025-31266—13.5%
——4——CVE-2025-3512—13.5%
——4There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to QTextMarkdownImporter to trigger the overflow.
This issue affects Qt from 6.8.0 to 6.8.4. Versions up to 6.6.0 are known to be unaffected, and the fix is in 6.8.4 and later.26dCVE-2024-26276—13.5%
——4——