Vulnerabilities exploitable today
360,835in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,641
- High11,455
- Medium7,085
- Low644
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-27941—12.1%
——4——CVE-2026-41182—12.1%
——4——CVE-2026-32347—12.1%
——4——CVE-2026-25415—12.1%
——4——CVE-2026-41313—12.1%
——4——CVE-2026-24945—12.1%
——4——CVE-2019-25619—12.1%
——4——CVE-2023-524855.5 MED12.1%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Wake DMCUB before sending a command
[Why]
We can hang in place trying to send commands when the DMCUB isn't
powered on.
[How]
For functions that execute within a DC context or DC lock we can
wrap the direct calls to dm_execute_dmub_cmd/list with code that
exits idle power optimizations and reallows once we're done with
the command submission on success.
For DM direct submissions the DM will need to manage the enter/exit
sequencing manually.
We cannot invoke a DMCUB command directly within the DM execution
helper or we can deadlock.3dCVE-2025-40669—12.1%
——4——CVE-2026-274225.3 MED12.1%
——4Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.26dCVE-2026-577658.5 HIG12.1%
——4Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.47dCVE-2025-36146—12.1%
——4——CVE-2026-396435.3 MED12.1%
——4Missing Authorization vulnerability in Payment Plugins Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Plugins for PayPal WooCommerce: from n/a through <= 2.0.13.25dCVE-2026-395625.3 MED12.1%
——4Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.10.25dCVE-2026-274185.3 MED12.1%
——4Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.26dCVE-2025-55629—12.1%
——4——CVE-2026-53949—12.1%
——4——CVE-2024-57838—12.1%
——4——CVE-2026-395885.3 MED12.1%
——4Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Lite: from n/a through <= 5.13.25dCVE-2026-647578.8 HIG12.1%
——4A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.12hCVE-2026-577568.5 HIG12.1%
——4Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.47dCVE-2024-22380—12.1%
——4——CVE-2023-28729—12.1%
——4——CVE-2025-2895—12.1%
——4——CVE-2024-43905—12.1%
——4——CVE-2026-84913.7 LOW12.1%
——4Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing.
This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.26dCVE-2026-24577—12.1%
——4——CVE-2026-3770—12.1%
——4——CVE-2026-38939—12.1%
——4——CVE-2026-32382—12.1%
——4——CVE-2025-12109—12.1%
——4——CVE-2026-13495—12.1%
——4——CVE-2026-32376—12.1%
——4——CVE-2026-32425—12.1%
——4——CVE-2024-43902—12.1%
——4——CVE-2026-396025.3 MED12.1%
——4Missing Authorization vulnerability in Rustaurius Order Tracking order-tracking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Tracking: from n/a through <= 3.4.3.25dCVE-2026-24116—12.1%
——4——CVE-2026-25364—12.1%
——4——CVE-2025-27260—12.1%
——4——CVE-2025-33226—12.1%
——4——