Vulnerabilities exploitable today
356,740in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,542
- High10,584
- Medium6,738
- Low665
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-115805.5 MED8.7%
——3The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.25dCVE-2026-2514—8.7%
——3——CVE-2025-58054—8.7%
——3——CVE-2021-29523—8.7%
——3——CVE-2023-53097—8.7%
——3——CVE-2023-2331—8.7%
——3——CVE-2025-64269—8.7%
——3——CVE-2021-29539—8.7%
——3——CVE-2026-41067—8.7%
——3——CVE-2021-29519—8.7%
——3——CVE-2026-24431—8.7%
——3——CVE-2021-47702—8.7%
——3——CVE-2022-254807.8 HIG8.7%
——3Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing to kernel memory beyond the SystemBuffer of the IRP.32dCVE-2021-29538—8.7%
——3——CVE-2022-49818—8.7%
——3——CVE-2021-29561—8.7%
——3——CVE-2023-53098—8.7%
——3——CVE-2021-29541—8.7%
——3——CVE-2023-538387.8 HIG8.7%
——3In the Linux kernel, the following vulnerability has been resolved:
f2fs: synchronize atomic write aborts
To fix a race condition between atomic write aborts, I use the inode
lock and make COW inode to be re-usable thoroughout the whole
atomic file inode lifetime.5dCVE-2021-29562—8.7%
——3——CVE-2024-53588—8.7%
——3——CVE-2024-50590—8.7%
——3——CVE-2021-29584—8.7%
——3——CVE-2021-29573—8.7%
——3——CVE-2024-8934—8.7%
——3——CVE-2025-66103—8.7%
——3——CVE-2026-140836.1 MED8.7%
——3Insufficient validation of untrusted input in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)39dCVE-2021-29580—8.7%
——3——CVE-2025-9549—8.7%
——3——CVE-2022-2402—8.7%
——3——CVE-2022-50364—8.7%
——3——CVE-2023-38524—8.7%
——3——CVE-2021-29543—8.7%
——3——CVE-2025-2998—8.7%
——3——CVE-2025-2999—8.7%
——3——CVE-2026-64040—8.7%
——3In the Linux kernel, the following vulnerability has been resolved:
cachefiles: Fix error return when vfs_mkdir() fails
When vfs_mkdir() fails, the error code is not extracted from the
returned error pointer. This causes mkdir_error to be reached with
ret=0, which leads to returning ERR_PTR(0) (NULL) instead of a
proper error pointer.
Fix this by extracting the error code from the error pointer when
vfs_mkdir() fails.10dCVE-2024-501197.0 HIG8.7%
——3In the Linux kernel, the following vulnerability has been resolved:
cifs: fix warning when destroy 'cifs_io_request_pool'
There's a issue as follows:
WARNING: CPU: 1 PID: 27826 at mm/slub.c:4698 free_large_kmalloc+0xac/0xe0
RIP: 0010:free_large_kmalloc+0xac/0xe0
Call Trace:
<TASK>
? __warn+0xea/0x330
mempool_destroy+0x13f/0x1d0
init_cifs+0xa50/0xff0 [cifs]
do_one_initcall+0xdc/0x550
do_init_module+0x22d/0x6b0
load_module+0x4e96/0x5ff0
init_module_from_file+0xcd/0x130
idempotent_init_module+0x330/0x620
__x64_sys_finit_module+0xb3/0x110
do_syscall_64+0xc1/0x1d0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Obviously, 'cifs_io_request_pool' is not created by mempool_create().
So just use mempool_exit() to revert 'cifs_io_request_pool'.5dCVE-2026-140686.1 MED8.7%
——3Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)39dCVE-2023-27316—8.7%
——3——CVE-2026-28868—8.7%
——3——