Vulnerabilities exploitable today
356,740in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,546
- High10,617
- Medium6,757
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-53813—8.6%
——3——CVE-2026-574077.2 HIG8.6%
——3Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2.27dCVE-2026-140804.3 MED8.6%
——3Insufficient validation of untrusted input in TabSwitcher in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Low)34dCVE-2024-56550—8.6%
——3——CVE-2024-45354—8.6%
——3——CVE-2022-34755—8.6%
——3——CVE-2026-573727.2 HIG8.6%
——3Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.27dCVE-2026-334152.7 LOW8.6%
——3Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from categories they were not authorized to view. Insufficient access controls on a sentiment analytics endpoint allowed category permission boundaries to be bypassed. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.16dCVE-2024-9493—8.6%
——3——CVE-2025-61431—8.6%
——3——CVE-2025-8280—8.6%
——3——CVE-2025-14316—8.6%
——3——CVE-2025-5281—8.6%
——3——CVE-2024-7021—8.6%
——3——CVE-2024-5684—8.6%
——3——CVE-2025-24790—8.6%
——3——CVE-2022-49796—8.6%
——3——CVE-2019-25584—8.6%
——3——CVE-2022-499447.8 HIG8.6%
——3In the Linux kernel, the following vulnerability has been resolved:
Revert "usb: typec: ucsi: add a common function ucsi_unregister_connectors()"
The recent commit 87d0e2f41b8c ("usb: typec: ucsi: add a common
function ucsi_unregister_connectors()") introduced a regression that
caused NULL dereference at reading the power supply sysfs. It's a
stale sysfs entry that should have been removed but remains with NULL
ops. The commit changed the error handling to skip the entries after
a NULL con->wq, and this leaves the power device unreleased.
For addressing the regression, the straight revert is applied here.
Further code improvements can be done from the scratch again.5dCVE-2025-563046.1 MED8.6%
——3Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.35dCVE-2026-140794.3 MED8.6%
——3Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)39dCVE-2024-235649.1 CRI8.6%
——3HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.23dCVE-2025-22084—8.6%
——3——CVE-2024-53682—8.6%
——3——CVE-2025-40265—8.6%
——3——CVE-2024-9495—8.6%
——3——CVE-2026-25034—8.6%
——3——CVE-2023-53056—8.6%
——3——CVE-2025-4394—8.6%
——3——CVE-2025-15466—8.6%
——3——CVE-2024-9491—8.6%
——3——CVE-2025-48132—8.6%
——3——CVE-2026-447433.7 LOW8.6%
——3Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information .This has a low impact on the confidentiality of the data. There is no impact on integrity and availability of the application.17dCVE-2026-137526.0 MED8.6%
——3Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to vulnerable command paths, causing Snowflake CLI to execute unintended SQL in the context of the user’s Snowflake session. Successful exploitation required crafted values to reach vulnerable parameters, including through socially engineered input, malicious repository configuration, or compromised automation feeding external values into the CLI, and impact is limited by the privileges assigned to the active session. The fix is available in Snowflake CLI version 3.19, and users must manually upgrade.40dCVE-2019-10556—8.6%
——3——CVE-2026-585987.0 HIG8.6%
——3Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.18dCVE-2024-53683—8.6%
——3——CVE-2024-20914—8.6%
——3——CVE-2024-38608—8.6%
——3——CVE-2025-9859—8.6%
——3——