Vulnerabilities exploitable today
356,750in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,532
- High10,540
- Medium6,698
- Low663
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-62523—8.8%
——3——CVE-2024-51539—8.8%
——3——CVE-2025-27432—8.8%
——3——CVE-2018-5910—8.8%
——3——CVE-2026-361829.8 CRI8.8%
——3GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack.18dCVE-2023-21286—8.8%
——3——CVE-2026-6046—8.8%
——3——CVE-2024-21245—8.8%
——3——CVE-2025-15537—8.8%
——3——CVE-2026-32014—8.8%
——3——CVE-2023-49699—8.8%
——3——CVE-2022-49822—8.8%
——3——CVE-2026-11775—8.8%
——3——CVE-2025-13722—8.8%
——3——CVE-2026-1399—8.8%
——3——CVE-2024-26934—8.8%
——3——CVE-2026-147593.3 LOW8.8%
——3A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The patch is named cd62d15a6cbecdc67fd03f3ebdbbbeb741d18f87. To fix this issue, it is recommended to deploy a patch.31dCVE-2021-35109—8.8%
——3——CVE-2021-35108—8.8%
——3——CVE-2025-15585—8.8%
——3——CVE-2025-11960—8.8%
——3——CVE-2026-22268—8.8%
——3——CVE-2026-7931—8.8%
——3——CVE-2024-35846—8.8%
——3——CVE-2025-21526—8.8%
——3——CVE-2025-59901—8.8%
——3——CVE-2022-43877—8.8%
——3——CVE-2024-36963—8.8%
——3——CVE-2023-53089—8.8%
——3——CVE-2024-25036—8.8%
——3——CVE-2023-53935—8.8%
——3——CVE-2026-8582—8.8%
——3——CVE-2026-33296—8.8%
——3——CVE-2023-29753—8.8%
——3——CVE-2026-75347.2 HIG8.8%
——3The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller` class unconditionally granting the custom `rs_earning_read` capability to all users — including unauthenticated visitors — combined with missing sanitization of the `reason` parameter in the `create_items()` function and missing output escaping in the `column_default()` method of `SRP_Master_Log`. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into the reward points log that will execute whenever an administrator accesses the Master Log or User Reward Points admin pages.17dCVE-2020-11174—8.8%
——3——CVE-2026-8870—8.8%
——3——CVE-2025-10612—8.8%
——3——CVE-2021-25506—8.8%
——3——CVE-2020-11120—8.8%
——3——