Vulnerabilities exploitable today
356,740in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,543
- High10,594
- Medium6,744
- Low665
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-36290—8.7%
——3——CVE-2023-51776—8.7%
——3——CVE-2026-27122—8.7%
——3——CVE-2026-3354—8.7%
——3——CVE-2025-7985—8.7%
——3——CVE-2023-25186—8.7%
——3——CVE-2025-62580—8.7%
——3——CVE-2026-44780—8.7%
——3——CVE-2025-58407—8.7%
——3——CVE-2025-0056—8.7%
——3——CVE-2020-11210—8.7%
——3——CVE-2024-9508—8.7%
——3——CVE-2026-395724.3 MED8.7%
——3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Retrieve Embedded Sensitive Data.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through < 5.6.5.16dCVE-2026-395664.3 MED8.7%
——3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress directorypress allows Retrieve Embedded Sensitive Data.This issue affects DirectoryPress: from n/a through <= 3.6.26.16dCVE-2025-37796—8.7%
——3——CVE-2023-20944—8.7%
——3——CVE-2025-15021—8.7%
——3——CVE-2025-8005—8.7%
——3——CVE-2025-29316—8.7%
——3——CVE-2023-54319—8.7%
——3——CVE-2019-2178—8.7%
——3——CVE-2025-7991—8.7%
——3——CVE-2023-31100—8.7%
——3——CVE-2022-3742—8.7%
——3——CVE-2024-26878—8.7%
——3——CVE-2026-112574.3 MED8.7%
——3Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)17dCVE-2025-55007—8.7%
——3——CVE-2025-8006—8.7%
——3——CVE-2025-11464—8.7%
——3——CVE-2025-7994—8.7%
——3——CVE-2025-62121—8.7%
——3——CVE-2026-27121—8.7%
——3——CVE-2025-62124—8.7%
——3——CVE-2025-8001—8.7%
——3——CVE-2025-8000—8.7%
——3——CVE-2024-27378—8.7%
——3——CVE-2025-7997—8.7%
——3——CVE-2026-21935—8.7%
——3——CVE-2024-410087.8 HIG8.7%
——3In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: change vm->task_info handling
This patch changes the handling and lifecycle of vm->task_info object.
The major changes are:
- vm->task_info is a dynamically allocated ptr now, and its uasge is
reference counted.
- introducing two new helper funcs for task_info lifecycle management
- amdgpu_vm_get_task_info: reference counts up task_info before
returning this info
- amdgpu_vm_put_task_info: reference counts down task_info
- last put to task_info() frees task_info from the vm.
This patch also does logistical changes required for existing usage
of vm->task_info.
V2: Do not block all the prints when task_info not found (Felix)
V3: Fixed review comments from Felix
- Fix wrong indentation
- No debug message for -ENOMEM
- Add NULL check for task_info
- Do not duplicate the debug messages (ti vs no ti)
- Get first reference of task_info in vm_init(), put last
in vm_fini()
V4: Fixed review comments from Felix
- fix double reference increment in create_task_info
- change amdgpu_vm_get_task_info_pasid
- additional changes in amdgpu_gem.c while porting5dCVE-2026-523706.1 MED8.7%
——3A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.4d