Vulnerabilities exploitable today
360,749in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,492
- High11,026
- Medium7,021
- Low631
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-3611—11.9%
——4——CVE-2026-24070—11.9%
——4——CVE-2024-10045—11.9%
——4——CVE-2023-22014—11.9%
——4——CVE-2025-41361—11.9%
——4——CVE-2025-10282—11.9%
——4——CVE-2026-20965—11.9%
——4——CVE-2025-28949—11.9%
——4——CVE-2024-56652—11.9%
——4——CVE-2024-7867—11.9%
——4——CVE-2025-59556—11.9%
——4——CVE-2022-487717.8 HIG11.9%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Fix stale file descriptors on failed usercopy
A failing usercopy of the fence_rep object will lead to a stale entry in
the file descriptor table as put_unused_fd() won't release it. This
enables userland to refer to a dangling 'file' object through that still
valid file descriptor, leading to all kinds of use-after-free
exploitation scenarios.
Fix this by deferring the call to fd_install() until after the usercopy
has succeeded.13dCVE-2022-33196—11.9%
——4——CVE-2022-29262—11.9%
——4——CVE-2025-611906.1 MED11.8%
——4A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover filtering functionality. The vulnerability exists due to improper sanitization of user-supplied input via the filter_type_1 parameter.42dCVE-2025-14893—11.8%
——4——CVE-2026-610564.8 MED11.8%
——4Vulnerability in the PeopleSoft Enterprise FIN Grants product of Oracle PeopleSoft (component: Grants). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Grants. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Grants accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Grants accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).12dCVE-2022-42328—11.8%
——4——CVE-2025-5296—11.8%
——4——CVE-2026-72011—11.8%
——4In the Linux kernel, the following vulnerability has been resolved:
s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
'level' is user space controlled and used to read from an array. Add the
missing array_index_nospec() call to prevent speculative execution.2dCVE-2025-1055—11.8%
——4——CVE-2024-2746—11.8%
——4——CVE-2024-52331—11.8%
——4——CVE-2026-482145.4 MED11.8%
——4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id POST parameter directly into an HTML form input value attribute and an inline JavaScript string literal. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered.24dCVE-2023-6057—11.8%
——4——CVE-2026-666924.3 MED11.8%
——4Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.4dCVE-2021-25355—11.8%
——4——CVE-2026-345986.1 MED11.8%
——4YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form title field. A malicious attacker can inject JavaScript without any authentication via a form title that is saved in the backend database. When any user visits that injected page, the JavaScript payload gets executed. This issue has been patched in version 4.6.0.23dCVE-2025-53122—11.8%
——4——CVE-2024-6628—11.8%
——4——CVE-2022-501377.8 HIG11.8%
——4In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: Fix a window for use-after-free
During a destroy CQ an interrupt may cause processing of a CQE after CQ
resources are freed by irdma_cq_free_rsrc(). Fix this by moving the call
to irdma_cq_free_rsrc() after the irdma_sc_cleanup_ceqes(), which is
called under the cq_lock.13dCVE-2019-25242—11.8%
——4——CVE-2022-50718—11.8%
——4——CVE-2026-482155.4 MED11.8%
——4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_id POST parameter directly into an HTML form input value attribute. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered.24dCVE-2021-25381—11.8%
——4——CVE-2025-399528.8 HIG11.8%
——4In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: avoid buffer overflow in WID string configuration
Fix the following copy overflow warning identified by Smatch checker.
drivers/net/wireless/microchip/wilc1000/wlan_cfg.c:184 wilc_wlan_parse_response_frame()
error: '__memcpy()' 'cfg->s[i]->str' copy overflow (512 vs 65537)
This patch introduces size check before accessing the memory buffer.
The checks are base on the WID type of received data from the firmware.
For WID string configuration, the size limit is determined by individual
element size in 'struct wilc_cfg_str_vals' that is maintained in 'len' field
of 'struct wilc_cfg_str'.18dCVE-2026-42379—11.8%
——4——CVE-2022-50729—11.8%
——4——CVE-2026-482195.4 MED11.8%
——4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered.24dCVE-2026-22027—11.8%
——4——