Vulnerabilities exploitable today
356,740in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,544
- High10,606
- Medium6,750
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-49813—8.7%
——3——CVE-2026-4596—8.7%
——3——CVE-2025-21073—8.7%
——3——CVE-2024-7477—8.7%
——3——CVE-2026-12033—8.7%
——3——CVE-2025-42921—8.7%
——3——CVE-2026-179824.3 MED8.6%
——3Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)6dCVE-2024-49817—8.7%
——3——CVE-2023-30728—8.7%
——3——CVE-2025-42913—8.7%
——3——CVE-2026-6755—8.7%
——3——CVE-2025-66445—8.7%
——3——CVE-2024-20306—8.6%
——3——CVE-2020-9065—8.7%
——3——CVE-2022-49790—8.7%
——3——CVE-2022-49887—8.7%
——3——CVE-2025-13391—8.7%
——3——CVE-2025-62070—8.7%
——3——CVE-2025-22046—8.7%
——3——CVE-2025-22070—8.7%
——3——CVE-2025-44951—8.7%
——3——CVE-2023-40368—8.7%
——3——CVE-2025-155655.3 MED8.7%
——3The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated attackers to mark pending WooCommerce orders as paid/completed.15dCVE-2026-599266.1 MED8.7%
——3Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even when HTMLRenderer escape mode is enabled. This issue is fixed in version 3.2.1.31dCVE-2026-111995.9 MED8.7%
——3Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)17dCVE-2026-27974—8.7%
——3——CVE-2026-563623.3 LOW8.7%
——3ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.30dCVE-2022-49800—8.7%
——3——CVE-2025-41388—8.7%
——3——CVE-2026-472546.1 MED8.7%
——3libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.cc` stores an out-of-bounds chunk index (`m_chunks.size()`) into `m_presentation_timeline` when the number of chunks defined in the `stco` box is less than the number of samples in `stsz`. A subsequent call to `heif_track_get_next_raw_sequence_sample()` reads `m_chunks[chunk_idx]` with that OOB index, causing a heap-buffer-overflow. Version 1.22.0 fixes the issue.13dCVE-2025-21821—8.7%
——3——CVE-2022-41290—8.7%
——3——CVE-2026-506587.0 HIG8.7%
——3Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.18dCVE-2026-24678.1 HIG8.7%
——3Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*.32dCVE-2016-3917—8.7%
——3——CVE-2023-53055—8.7%
——3——CVE-2023-530337.8 HIG8.7%
——3In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits
If the offset + length goes over the ethernet + vlan header, then the
length is adjusted to copy the bytes that are within the boundaries of
the vlan_ethhdr scratchpad area. The remaining bytes beyond ethernet +
vlan header are copied directly from the skbuff data area.
Fix incorrect arithmetic operator: subtract, not add, the size of the
vlan header in case of double-tagged packets to adjust the length
accordingly to address CVE-2023-0179.5dCVE-2025-22032—8.7%
——3——CVE-2024-8690—8.6%
——3——CVE-2019-10502—8.6%
——3——