Vulnerabilities exploitable today
356,750in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,532
- High10,540
- Medium6,698
- Low663
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-62912—8.9%
——3——CVE-2026-395205.3 MED8.9%
——3Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weDocs: from n/a through <= 2.1.18.16dCVE-2025-62942—8.9%
——3——CVE-2025-49908—8.9%
——3——CVE-2025-0649—8.9%
——3——CVE-2023-3108—8.8%
——3——CVE-2025-38706—8.8%
——3——CVE-2025-8490—8.8%
——3——CVE-2025-55165—8.8%
——3——CVE-2025-60208—8.8%
——3——CVE-2025-30062—8.8%
——3——CVE-2023-39253—8.8%
——3——CVE-2021-41225—8.8%
——3——CVE-2025-12095—8.8%
——3——CVE-2019-2236—8.8%
——3——CVE-2020-10125—8.8%
——3——CVE-2024-41983—8.8%
——3——CVE-2022-504138.8 HIG8.8%
——3In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free
We've already freed the assoc_data at this point, so need
to use another copy of the AP (MLD) address instead.6dCVE-2025-58134—8.8%
——3——CVE-2025-22105—8.8%
——3——CVE-2025-6272—8.8%
——3——CVE-2025-53222—8.8%
——3——CVE-2025-1292—8.8%
——3——CVE-2023-52578—8.8%
——3——CVE-2026-124217.2 HIG8.8%
——3The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.17dCVE-2025-62375—8.8%
——3——CVE-2026-7935—8.8%
——3——CVE-2024-8091—8.8%
——3——CVE-2023-39932—8.8%
——3——CVE-2025-64400—8.8%
——3——CVE-2020-3696—8.8%
——3——CVE-2026-147893.3 LOW8.8%
——3A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of the file libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. Performing a manipulation results in stack-based buffer overflow. The attack requires a local approach. The exploit is now public and may be used. The patch is named 175d4addb68981331c85b10681c2161c38fb5762. It is suggested to install a patch to address this issue.31dCVE-2026-1265—8.8%
——3——CVE-2021-47089—8.8%
——3——CVE-2023-39259—8.8%
——3——CVE-2023-30692—8.8%
——3——CVE-2026-12458—8.8%
——3——CVE-2022-21794—8.8%
——3——CVE-2026-23967—8.8%
——3——CVE-2025-5481—8.8%
——3——