Vulnerabilities exploitable today
356,750in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,532
- High10,539
- Medium6,697
- Low663
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-32647—8.9%
——3——CVE-2025-58235—8.9%
——3——CVE-2025-50869—8.9%
——3——CVE-2026-331855.0 MED8.9%
——3Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the group email settings test endpoint could be used to make the server initiate outbound connections to arbitrary hosts and ports. This could allow probing of internal network infrastructure. The endpoint was accessible to non-staff group owners. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.16dCVE-2022-49940—8.9%
——3——CVE-2026-179554.3 MED8.9%
——3Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)6dCVE-2019-3805—8.9%
——3——CVE-2025-60099—8.9%
——3——CVE-2024-27853—8.9%
——3——CVE-2025-59569—8.9%
——3——CVE-2025-62923—8.9%
——3——CVE-2024-449957.8 HIG8.9%
——3In the Linux kernel, the following vulnerability has been resolved:
net: hns3: fix a deadlock problem when config TC during resetting
When config TC during the reset process, may cause a deadlock, the flow is
as below:
pf reset start
│
▼
......
setup tc │
│ ▼
▼ DOWN: napi_disable()
napi_disable()(skip) │
│ │
▼ ▼
...... ......
│ │
▼ │
napi_enable() │
▼
UINIT: netif_napi_del()
│
▼
......
│
▼
INIT: netif_napi_add()
│
▼
...... global reset start
│ │
▼ ▼
UP: napi_enable()(skip) ......
│ │
▼ ▼
...... napi_disable()
In reset process, the driver will DOWN the port and then UINIT, in this
case, the setup tc process will UP the port before UINIT, so cause the
problem. Adds a DOWN process in UINIT to fix it.6dCVE-2025-58220—8.9%
——3——CVE-2026-111956.5 MED8.9%
——3Inappropriate implementation in MHTML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)18dCVE-2019-25569—8.9%
——3——CVE-2025-62937—8.9%
——3——CVE-2025-62940—8.9%
——3——CVE-2026-152954.4 MED8.9%
——3The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.26dCVE-2025-62941—8.9%
——3——CVE-2024-50006—8.9%
——3——CVE-2026-646355.3 MED8.9%
——3Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.10dCVE-2022-49849—8.9%
——3——CVE-2025-62917—8.9%
——3——CVE-2025-43407—8.9%
——3——CVE-2025-64194—8.9%
——3——CVE-2025-58652—8.9%
——3——CVE-2025-62030—8.9%
——3——CVE-2025-62032—8.9%
——3——CVE-2025-62949—8.9%
——3——CVE-2026-54070—8.9%
——3——CVE-2019-2128—8.9%
——3——CVE-2025-58001—8.9%
——3——CVE-2025-62951—8.9%
——3——CVE-2024-37086—8.9%
——3——CVE-2026-59196.5 MED8.9%
——3Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)17dCVE-2026-625075.3 MED8.9%
——3Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N).12dCVE-2025-14725—8.9%
——3——CVE-2025-58691—8.9%
——3——CVE-2026-179454.3 MED8.9%
——3Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)6dCVE-2025-62907—8.9%
——3——