Vulnerabilities exploitable today
356,768in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,533
- High10,540
- Medium6,708
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-5889—8.9%
——3——CVE-2018-5858—8.9%
——3——CVE-2024-35836—8.9%
——3——CVE-2024-34756—8.9%
——3——CVE-2025-21940—8.9%
——3——CVE-2025-55904—8.9%
——3——CVE-2026-558776.1 MED8.9%
——3Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or Iconify on-demand JSON body responses containing nested script elements, on* event handlers, or dangerous URL schemes to execute cross-site scripting. This issue is fixed in versions 2.36.1 and 3.2.0.30dCVE-2019-10530—8.9%
——3——CVE-2025-39997—8.9%
——3——CVE-2026-5325—8.9%
——3——CVE-2018-11275—8.9%
——3——CVE-2026-27927—8.9%
——3——CVE-2026-2029—8.9%
——3——CVE-2026-42642—8.9%
——3——CVE-2023-53730—8.9%
——3——CVE-2023-43612—8.9%
——3——CVE-2022-509616.4 MED8.9%
——3WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when administrators or other authenticated users visit the plugin settings page.17dCVE-2025-377637.8 HIG8.9%
——3In the Linux kernel, the following vulnerability has been resolved:
drm/imagination: take paired job reference
For paired jobs, have the fragment job take a reference on the
geometry job, so that the geometry job cannot be freed until
the fragment job has finished with it.
The geometry job structure is accessed when the fragment job is being
prepared by the GPU scheduler. Taking the reference prevents the
geometry job being freed until the fragment job no longer requires it.
Fixes a use after free bug detected by KASAN:
[ 124.256386] BUG: KASAN: slab-use-after-free in pvr_queue_prepare_job+0x108/0x868 [powervr]
[ 124.264893] Read of size 1 at addr ffff0000084cb960 by task kworker/u16:4/6311dCVE-2023-53044—8.9%
——3——CVE-2025-43476—8.9%
——3——CVE-2026-6216—8.9%
——3——CVE-2025-52374—8.9%
——3——CVE-2025-59787—8.9%
——3——CVE-2026-4354—8.9%
——3——CVE-2025-68521—8.9%
——3——CVE-2026-4355—8.9%
——3——CVE-2022-50374—8.9%
——3——CVE-2025-2168—8.9%
——3——CVE-2026-6745—8.9%
——3——CVE-2019-2333—8.9%
——3——CVE-2022-50356—8.9%
——3——CVE-2025-53393—8.9%
——3——CVE-2025-22520—8.9%
——3——CVE-2024-44123—8.9%
——3——CVE-2025-21942—8.9%
——3——CVE-2026-45389—8.9%
——3——CVE-2025-52779—8.9%
——3——CVE-2025-3611—8.9%
——3——CVE-2025-49917—8.9%
——3——CVE-2026-33982—8.9%
——3——