Vulnerabilities exploitable today
360,835in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,641
- High11,455
- Medium7,085
- Low644
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-49371—12.0%
——4——CVE-2026-25594—12.0%
——4——CVE-2026-503257.0 HIG12.0%
——4Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.27dCVE-2024-47663—12.0%
——4——CVE-2022-30716—12.0%
——4——CVE-2024-57991—12.0%
——4——CVE-2026-98908.3 HIG12.0%
——4Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)28dCVE-2026-99058.3 HIG12.0%
——4Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)28dCVE-2025-22807—12.0%
——4——CVE-2024-7994—12.0%
——4——CVE-2026-99668.3 HIG12.0%
——4Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)28dCVE-2026-33015—12.0%
——4——CVE-2026-690876.5 MED12.0%
——4The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When a form blueprint defines a redirect target such as redirect: "{{ form.value('next') }}" using an attacker-controllable field, an unauthenticated form submitter can supply a value like https://evil.com to cause a 302 redirect to an arbitrary external site, enabling phishing.15dCVE-2025-50422—12.0%
——4——CVE-2025-23293—12.0%
——4——CVE-2024-43815—12.0%
——4——CVE-2025-21774—12.0%
——4——CVE-2025-68115—12.0%
——4——CVE-2024-36935—12.0%
——4——CVE-2025-11462—12.0%
——4——CVE-2026-127384.3 MED12.0%
——4The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the status of arbitrary posts and pages to 'draft', effectively unpublishing arbitrary site content.35dCVE-2025-22362—12.0%
——4——CVE-2026-98958.3 HIG12.0%
——4Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)28dCVE-2026-32080—12.0%
——4——CVE-2023-3674—12.0%
——4——CVE-2024-6925—12.0%
——4——CVE-2024-517297.8 HIG12.0%
——4In the Linux kernel, the following vulnerability has been resolved:
mm: use aligned address in copy_user_gigantic_page()
In current kernel, hugetlb_wp() calls copy_user_large_folio() with the
fault address. Where the fault address may be not aligned with the huge
page size. Then, copy_user_large_folio() may call
copy_user_gigantic_page() with the address, while
copy_user_gigantic_page() requires the address to be huge page size
aligned. So, this may cause memory corruption or information leak,
addtional, use more obvious naming 'addr_hint' instead of 'addr' for
copy_user_gigantic_page().14dCVE-2025-13125—12.0%
——4——CVE-2025-26058—12.0%
——4——CVE-2026-98998.3 HIG12.0%
——4Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)28dCVE-2022-50814—12.0%
——4——CVE-2026-98888.3 HIG12.0%
——4Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)28dCVE-2023-40121—12.0%
——4——CVE-2026-8571—12.0%
——4——CVE-2025-22327—12.0%
——4——CVE-2022-50830—12.0%
——4——CVE-2022-254775.5 MED12.0%
——4Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.40dCVE-2022-33708—12.0%
——4——CVE-2024-56554—12.0%
——4——CVE-2025-22584—12.0%
——4——