Vulnerabilities exploitable today
359,691in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,519
- High11,197
- Medium7,131
- Low645
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-39393—11.1%
——3——CVE-2024-266377.8 HIG11.1%
——3In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: rely on mac80211 debugfs handling for vif
mac80211 started to delete debugfs entries in certain cases, causing a
ath11k to crash when it tried to delete the entries later. Fix this by
relying on mac80211 to delete the entries when appropriate and adding
them from the vif_add_debugfs handler.11dCVE-2021-41061—11.1%
——3——CVE-2025-39372—11.1%
——3——CVE-2025-49934—11.1%
——3——CVE-2025-39407—11.1%
——3——CVE-2026-32839—11.1%
——3——CVE-2026-24256.1 MED11.1%
——3The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link.24dCVE-2025-49929—11.1%
——3——CVE-2021-474105.5 MED11.1%
——3In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: fix svm_migrate_fini warning
Device manager releases device-specific resources when a driver
disconnects from a device, devm_memunmap_pages and
devm_release_mem_region calls in svm_migrate_fini are redundant.
It causes below warning trace after patch "drm/amdgpu: Split
amdgpu_device_fini into early and late", so remove function
svm_migrate_fini.
BUG: https://gitlab.freedesktop.org/drm/amd/-/issues/1718
WARNING: CPU: 1 PID: 3646 at drivers/base/devres.c:795
devm_release_action+0x51/0x60
Call Trace:
? memunmap_pages+0x360/0x360
svm_migrate_fini+0x2d/0x60 [amdgpu]
kgd2kfd_device_exit+0x23/0xa0 [amdgpu]
amdgpu_amdkfd_device_fini_sw+0x1d/0x30 [amdgpu]
amdgpu_device_fini_sw+0x45/0x290 [amdgpu]
amdgpu_driver_release_kms+0x12/0x30 [amdgpu]
drm_dev_release+0x20/0x40 [drm]
release_nodes+0x196/0x1e0
device_release_driver_internal+0x104/0x1d0
driver_detach+0x47/0x90
bus_remove_driver+0x7a/0xd0
pci_unregister_driver+0x3d/0x90
amdgpu_exit+0x11/0x20 [amdgpu]4dCVE-2026-2483—11.1%
——3——CVE-2021-47363—11.1%
——3——CVE-2026-449245.4 MED11.1%
——3InfoScale VIOM 9.1.3 allows XSS.23dCVE-2025-58228—11.1%
——3——CVE-2023-40210—11.1%
——3——CVE-2024-3454—11.1%
——3——CVE-2026-647838.8 HIG11.1%
——3A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.18dCVE-2022-48890—11.1%
——3——CVE-2025-23979—11.1%
——3——CVE-2024-31435—11.1%
——3——CVE-2025-66025—11.1%
——3——CVE-2022-27493—11.1%
——3——CVE-2026-14516.1 MED11.1%
——3The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.24dCVE-2026-336845.3 MED11.1%
——3WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during account registration. The set_api_signUp method in the API plugin accepts emailVerified, canUpload, canStream, and canCreateMeet parameters from user-supplied input and applies them to newly created accounts without verifying that the request was authenticated with a valid APISecret. By self-granting account attributes, attackers can mark their own accounts as email-verified without owning the address (bypassing email-gated functionality) and award themselves upload, streaming, and meeting-creation permissions, circumventing administrator access controls that intentionally restrict these capabilities for new users. This issue has been fixed in version 29.030dCVE-2021-26364—11.1%
——3——CVE-2025-57989—11.1%
——3——CVE-2025-47822—11.1%
——3——CVE-2025-57967—11.1%
——3——CVE-2025-6549—11.1%
——3——CVE-2026-489556.5 MED11.1%
——3An improper access check allows unauthorized users to access workflow stage and transition information.37dCVE-2023-45647—11.1%
——3——CVE-2025-68162—11.1%
——3——CVE-2016-20033—11.1%
——3——CVE-2025-23988—11.1%
——3——CVE-2025-39392—11.1%
——3——CVE-2023-45645—11.1%
——3——CVE-2020-8704—11.1%
——3——CVE-2024-31932—11.1%
——3——CVE-2025-49939—11.1%
——3——CVE-2024-28183—11.1%
——3——