Vulnerabilities exploitable today
356,923in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,543
- High10,564
- Medium6,729
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-4224—9.3%
——3——CVE-2024-37518—9.3%
——3——CVE-2023-23580—9.3%
——3——CVE-2024-45401—9.3%
——3——CVE-2026-54829—9.3%
——3——CVE-2024-38763—9.3%
——3——CVE-2023-21255—9.3%
——3——CVE-2026-23027—9.3%
——3——CVE-2021-36279—9.3%
——3——CVE-2026-29933—9.3%
——3——CVE-2025-48916—9.3%
——3——CVE-2026-178987.5 HIG9.3%
——3Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)7dCVE-2026-160424.3 MED9.3%
——3The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.6dCVE-2026-0932—9.3%
——3——CVE-2026-183695.8 MED9.3%
——3A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.11dCVE-2026-160354.3 MED9.3%
——3The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.6dCVE-2022-48681—9.3%
——3——CVE-2024-37511—9.3%
——3——CVE-2024-4867—9.3%
——3——CVE-2026-62659—9.3%
——3A
security flaw was discovered in the NETGEAR WAX333 Access Point that could
allow someone already logged in and connected to the local network to make
unauthorized changes to the device's settings26dCVE-2023-30651—9.3%
——3——CVE-2026-59158.1 HIG9.3%
——3Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)17dCVE-2025-40903—9.3%
——3——CVE-2025-47128—9.3%
——3——CVE-2024-37543—9.3%
——3——CVE-2026-8538—9.3%
——3——CVE-2026-705904.8 MED9.3%
——3Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with a recovered password. Depending on the database used, leaked hashes may not have had the correct casing for all characters, increasing the difficulty of a password-guessing attack. This issue is fixed in version 6.54.1.5dCVE-2024-37467—9.3%
——3——CVE-2023-21506—9.3%
——3——CVE-2021-35103—9.3%
——3——CVE-2021-34409—9.3%
——3——CVE-2025-40901—9.3%
——3——CVE-2025-399339.4 CRI9.3%
——3In the Linux kernel, the following vulnerability has been resolved:
smb: client: let recv_done verify data_offset, data_length and remaining_data_length
This is inspired by the related server fixes.11dCVE-2025-47121—9.3%
——3——CVE-2024-37238—9.3%
——3——CVE-2023-30650—9.3%
——3——CVE-2021-35105—9.3%
——3——CVE-2026-585174.3 MED9.3%
——3Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass.
This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.31dCVE-2025-658078.4 HIG9.3%
——3An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.37dCVE-2022-50210—9.3%
——3——