Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,687
- High11,543
- Medium7,255
- Low674
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-58624—10.6%
——3——CVE-2026-627747.0 HIG10.6%
——3Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.2dCVE-2025-58808—10.6%
——3——CVE-2025-9308—10.6%
——3——CVE-2026-657807.0 HIG10.6%
——3Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.1dCVE-2024-502887.8 HIG10.6%
——3In the Linux kernel, the following vulnerability has been resolved:
media: vivid: fix buffer overwrite when using > 32 buffers
The maximum number of buffers that can be requested was increased to
64 for the video capture queue. But video capture used a must_blank
array that was still sized for 32 (VIDEO_MAX_FRAME). This caused an
out-of-bounds write when using buffer indices >= 32.
Create a new define MAX_VID_CAP_BUFFERS that is used to access the
must_blank array and set max_num_buffers for the video capture queue.
This solves a crash reported by:
https://bugzilla.kernel.org/show_bug.cgi?id=2192589dCVE-2026-692239.1 CRI10.6%
——3Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommended to upgrade to version 1.19.1, which fixes the issue.19hCVE-2022-499567.0 HIG10.6%
——3In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8712: fix use after free bugs
_Read/Write_MACREG callbacks are NULL so the read/write_macreg_hdl()
functions don't do anything except free the "pcmd" pointer. It
results in a use after free. Delete them.9dCVE-2022-28774—10.6%
——3——CVE-2021-47754—10.6%
——3——CVE-2025-37916—10.6%
——3——CVE-2025-58842—10.6%
——3——CVE-2026-42984.3 MED10.6%
——3The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.35dCVE-2020-28398—10.6%
——3——CVE-2024-8207—10.6%
——3——CVE-2024-22276—10.6%
——3——CVE-2024-54541—10.5%
——3——CVE-2025-58614—10.6%
——3——CVE-2025-14426—10.6%
——3——CVE-2024-3779—10.6%
——3——CVE-2023-42870—10.6%
——3——CVE-2025-60104—10.6%
——3——CVE-2026-45021—10.6%
——3——CVE-2026-2489—10.6%
——3——CVE-2026-395102.7 LOW10.6%
——3Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.11.20dCVE-2021-20490—10.6%
——3——CVE-2024-35138—10.6%
——3——CVE-2024-32863—10.6%
——3——CVE-2021-29615—10.6%
——3——CVE-2022-22646—10.6%
——3——CVE-2025-7052—10.6%
——3——CVE-2022-36955—10.6%
——3——CVE-2024-51072—10.6%
——3——CVE-2025-58655—10.6%
——3——CVE-2025-5256—10.6%
——3——CVE-2023-20563—10.6%
——3——CVE-2022-27608—10.6%
——3——CVE-2025-49061—10.6%
——3——CVE-2023-20210—10.6%
——3——CVE-2025-15146—10.6%
——3——