Vulnerabilities exploitable today
359,428in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,475
- High11,085
- Medium7,046
- Low645
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-60070—10.8%
——3——CVE-2026-40096—10.8%
——3——CVE-2025-21168—10.8%
——3——CVE-2025-10727—10.8%
——3——CVE-2004-1022—10.8%
——3——CVE-2026-4083—10.8%
——3——CVE-2024-54428—10.8%
——3——CVE-2024-23444—10.8%
——3——CVE-2026-101526.3 MED10.8%
——3A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation results in improper access controls. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.24dCVE-2023-25940—10.8%
——3——CVE-2025-41696—10.8%
——3——CVE-2022-46722—10.8%
——3——CVE-2025-40721—10.8%
——3——CVE-2025-21652—10.8%
——3——CVE-2023-39537—10.8%
——3——CVE-2024-57888—10.8%
——3——CVE-2024-23803—10.8%
——3——CVE-2026-76236.4 MED10.8%
——3The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.2dCVE-2024-51656—10.8%
——3——CVE-2026-23236—10.8%
——3——CVE-2025-53659—10.8%
——3——CVE-2026-467488.8 HIG10.8%
——3A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system.23dCVE-2022-22141—10.8%
——3——CVE-2026-1598—10.8%
——3——CVE-2024-27629—10.8%
——3——CVE-2023-46928—10.8%
——3——CVE-2026-149876.4 MED10.8%
——3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with give worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes specifically when a donor clicks the Share on Twitter button on the Sequoia donation confirmation view, as that is when the unescaped twitter_message value is evaluated inside the JavaScript template literal.29dCVE-2024-8313—10.8%
——3——CVE-2026-63882—10.8%
——3In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: fix NULL pointer bug in svm_range_set_attr
The process_info could be NULL if user doesn't call kfd_ioctl_acquire_vm
before calling kfd_ioctl_svm.
(cherry picked from commit 83a26c812e0529eb040d31a76f73e33e637243d4)18dCVE-2025-9394—10.8%
——3——CVE-2024-31954—10.8%
——3——CVE-2022-50361—10.8%
——3——CVE-2022-49824—10.8%
——3——CVE-2024-51643—10.8%
——3——CVE-2026-0674—10.8%
——3——CVE-2024-51655—10.8%
——3——CVE-2024-12545—10.8%
——3——CVE-2025-66382—10.8%
——3——CVE-2024-54412—10.8%
——3——CVE-2024-54421—10.8%
——3——