Vulnerabilities exploitable today
360,835in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,641
- High11,456
- Medium7,085
- Low644
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-36287—12.1%
——4——CVE-2025-21781—12.1%
——4——CVE-2025-31471—12.1%
——4——CVE-2023-35763—12.1%
——4——CVE-2025-49375—12.1%
——4——CVE-2023-45749—12.1%
——4——CVE-2025-5648—12.1%
——4——CVE-2023-45605—12.1%
——4——CVE-2026-2707—12.1%
——4——CVE-2026-151427.5 HIG12.1%
——4The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID during user capability checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit an administrator account and escalate their privileges to Administrator when the targeted user ID matches the ID of an existing media attachment.16hCVE-2020-1882—12.1%
——4——CVE-2023-45273—12.1%
——4——CVE-2024-53139—12.1%
——4——CVE-2025-30997—12.1%
——4——CVE-2023-44994—12.1%
——4——CVE-2025-46541—12.1%
——4——CVE-2025-32992—12.1%
——4——CVE-2024-56544—12.1%
——4——CVE-2026-720989.8 CRI12.1%
——4In the Linux kernel, the following vulnerability has been resolved:
dm-verity: fix buffer overflow in FEC calculation
There's a buffer overflow in dm-verity-fec:
if (neras && *neras <= v->fec->roots)
fio->erasures[(*neras)++] = i;
This allows *neras to reach roots + 1 (the post-increment pushes it past
roots). This value is then passed as no_eras to decode_rs8(). Inside the
RS decoder (lib/reed_solomon/decode_rs.c:113-121), the erasure locator
polynomial loop writes lambda[j] where j can reach nroots + 1 — one
element past the end of lambda[] (which is sized nroots + 1, valid
indices 0..nroots). The out-of-bounds write lands on syn[0], corrupting
the syndrome buffer.1dCVE-2026-164018.8 HIG12.1%
——4Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.24dCVE-2026-116947.5 HIG12.1%
——4Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)26dCVE-2026-24556—12.1%
——4——CVE-2020-1872—12.1%
——4——CVE-2025-47727—12.1%
——4——CVE-2023-41694—12.1%
——4——CVE-2023-32646—12.1%
——4——CVE-2026-22348—12.1%
——4——CVE-2026-654535.3 MED12.1%
——4Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.26dCVE-2024-53067—12.1%
——4——CVE-2025-47725—12.1%
——4——CVE-2025-31473—12.1%
——4——CVE-2025-46517—12.1%
——4——CVE-2025-47726—12.1%
——4——CVE-2026-32094—12.1%
——4——CVE-2026-395095.3 MED12.1%
——4Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10.24dCVE-2025-47665—12.1%
——4——CVE-2025-31464—12.1%
——4——CVE-2026-25000—12.1%
——4——CVE-2023-45651—12.1%
——4——CVE-2022-48942—12.1%
——4——