Vulnerabilities exploitable today
363,850in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,846
- High11,701
- Medium7,103
- Low667
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-544324.7 MED13.0%
——4Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.37dCVE-2025-48062—13.0%
——4——CVE-2023-28428—13.0%
——4——CVE-2026-667743.7 LOW13.0%
——4SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity.10dCVE-2025-53286—12.9%
——4——CVE-2025-55001—12.9%
——4——CVE-2024-20871—12.9%
——4——CVE-2026-100097.5 HIG12.9%
——4Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)31dCVE-2024-31238—12.9%
——4——CVE-2025-24116—12.9%
——4——CVE-2026-7688—12.9%
——4——CVE-2025-22726—12.9%
——4——CVE-2024-31573—12.9%
——4——CVE-2025-53239—12.9%
——4——CVE-2024-35902—12.9%
——4——CVE-2024-12220—12.9%
——4——CVE-2025-21751—12.9%
——4——CVE-2023-52698—12.9%
——4——CVE-2025-52764—12.9%
——4——CVE-2025-59006—12.9%
——4——CVE-2025-12075—12.9%
——4——CVE-2025-49390—12.9%
——4——CVE-2026-57630—12.9%
——4——CVE-2020-37105—12.9%
——4——CVE-2026-31413—12.9%
——4——CVE-2026-395435.3 MED12.9%
——4Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.21.4.28dCVE-2026-143175.3 MED12.9%
——4The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled.21dCVE-2024-46715—12.9%
——4——CVE-2023-21969—12.9%
——4——CVE-2025-14688—12.9%
——4——CVE-2026-28433—12.9%
——4——CVE-2024-410197.8 HIG12.9%
——4In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Validate ff offset
This adds sanity checks for ff offset. There is a check
on rt->first_free at first, but walking through by ff
without any check. If the second ff is a large offset.
We may encounter an out-of-bound read.17dCVE-2016-200637.1 HIG12.9%
——4Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attackers can access the admin interface and supply crafted SQL statements in the message parameter to extract sensitive database information including user credentials and site configuration data.32dCVE-2023-51489—12.9%
——4——CVE-2026-2644—12.9%
——4——CVE-2025-6037—12.9%
——4——CVE-2026-100037.5 HIG12.9%
——4Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)31dCVE-2022-31622—12.9%
——4——CVE-2015-8955—12.9%
——4——CVE-2023-48645—12.9%
——4——