Vulnerabilities exploitable today
356,750in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,532
- High10,540
- Medium6,698
- Low663
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-49344—8.8%
——3——CVE-2026-415696.1 MED8.8%
——3authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper URL parsing. An attacker who can craft a login link can supply a wreply value on a different origin that passes the check (e.g. https://portal.example.com.evil.tld/), causing the victim's browser to POST the signed WS-Federation login response to attacker-controlled infrastructure. This issue has been patched in version 2026.2.3.18dCVE-2025-29478—8.8%
——3——CVE-2026-1338—8.8%
——3——CVE-2026-144065.9 MED8.8%
——3Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)38dCVE-2026-37596—8.8%
——3——CVE-2026-1663—8.8%
——3——CVE-2024-47942—8.8%
——3——CVE-2025-3527—8.8%
——3——CVE-2025-10751—8.8%
——3——CVE-2025-10552—8.8%
——3——CVE-2024-33222—8.8%
——3——CVE-2025-12886—8.8%
——3——CVE-2025-378237.8 HIG8.8%
——3In the Linux kernel, the following vulnerability has been resolved:
net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too
Similarly to the previous patch, we need to safe guard hfsc_dequeue()
too. But for this one, we don't have a reliable reproducer.11dCVE-2026-483747.8 HIG8.8%
——3Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.6dCVE-2025-575715.6 MED8.8%
——3Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT.36dCVE-2026-49214—8.8%
——3——CVE-2022-4294—8.8%
——3——CVE-2025-65297—8.8%
——3——CVE-2026-30239—8.8%
——3——CVE-2023-5760—8.8%
——3——CVE-2024-1470—8.8%
——3——CVE-2020-3622—8.8%
——3——CVE-2026-24176—8.8%
——3——CVE-2026-1613—8.8%
——3——CVE-2023-21509—8.8%
——3——CVE-2019-14078—8.8%
——3——CVE-2023-30670—8.8%
——3——CVE-2025-12508—8.8%
——3——CVE-2026-2541—8.8%
——3——CVE-2026-36944—8.8%
——3——CVE-2025-68708—8.8%
——3——CVE-2026-53442—8.8%
——3——CVE-2026-37601—8.8%
——3——CVE-2026-1923—8.8%
——3——CVE-2025-11737—8.8%
——3——CVE-2025-11723—8.8%
——3——CVE-2022-36442—8.8%
——3——CVE-2026-152575.3 MED8.8%
——3The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts.10dCVE-2026-1570—8.8%
——3——