Vulnerabilities exploitable today
358,921in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,707
- High11,664
- Medium7,446
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-257206.5 MED10.0%
——3Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot the monitor by sending a malformed network packet. Attackers can repeatedly send such malformed packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.22dCVE-2022-49996—10.0%
——3——CVE-2024-49343—10.0%
——3——CVE-2024-50144—10.0%
——3——CVE-2024-4534—10.0%
——3——CVE-2022-29263—10.0%
——3——CVE-2024-36578—10.0%
——3——CVE-2020-0033—10.0%
——3——CVE-2024-12903—10.0%
——3——CVE-2025-48962—10.0%
——3——CVE-2023-3670—10.0%
——3——CVE-2026-13534—10.0%
——3——CVE-2022-34460—10.0%
——3——CVE-2026-646238.6 HIG10.0%
——3Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.21dCVE-2023-6154—10.0%
——3——CVE-2026-35642—10.0%
——3——CVE-2020-9102—10.0%
——3——CVE-2023-42934—10.0%
——3——CVE-2024-40603—10.0%
——3——CVE-2026-631434.3 MED10.0%
——3Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.10dCVE-2023-40084—10.0%
——3——CVE-2024-22450—10.0%
——3——CVE-2025-21729—10.0%
——3——CVE-2024-41085—10.0%
——3——CVE-2023-53081—10.0%
——3——CVE-2026-29246.4 MED10.0%
——3The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoad' parameter in versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.20dCVE-2026-0827—10.0%
——3——CVE-2025-218087.8 HIG10.0%
——3In the Linux kernel, the following vulnerability has been resolved:
net: xdp: Disallow attaching device-bound programs in generic mode
Device-bound programs are used to support RX metadata kfuncs. These
kfuncs are driver-specific and rely on the driver context to read the
metadata. This means they can't work in generic XDP mode. However, there
is no check to disallow such programs from being attached in generic
mode, in which case the metadata kfuncs will be called in an invalid
context, leading to crashes.
Fix this by adding a check to disallow attaching device-bound programs
in generic mode.14dCVE-2025-12441—10.0%
——3——CVE-2026-96296.4 MED10.0%
——3The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.21dCVE-2025-54870—10.0%
——3——CVE-2024-5003—10.0%
——3——CVE-2024-56674—10.0%
——3——CVE-2026-0948—10.0%
——3——CVE-2025-30788—10.0%
——3——CVE-2025-54811—10.0%
——3——CVE-2025-6680—10.0%
——3——CVE-2026-06266.4 MED10.0%
——3The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping of the 'button_icon' parameter. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.20dCVE-2022-49973—10.0%
——3——CVE-2025-65380—10.0%
——3——