Vulnerabilities exploitable today
356,708in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,545
- High10,617
- Medium6,752
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-2722—8.5%
——3——CVE-2025-125063.5 LOW8.5%
——3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution.31dCVE-2025-12475—8.5%
——3——CVE-2026-49053—8.5%
——3——CVE-2026-125175.3 MED8.5%
——3The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and private-network URLs and read back the parsed page metadata. This is a Server-Side Request Forgery.31dCVE-2023-4000—8.5%
——3——CVE-2025-57681—8.5%
——3——CVE-2024-40709—8.5%
——3——CVE-2026-125165.3 MED8.5%
——3The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body. This results in a full-read Server-Side Request Forgery and open proxy.31dCVE-2026-111066.5 MED8.5%
——3Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)17dCVE-2026-40341—8.5%
——3——CVE-2025-67916—8.5%
——3——CVE-2025-68297—8.5%
——3——CVE-2025-69085—8.5%
——3——CVE-2025-64326—8.5%
——3——CVE-2025-23649—8.5%
——3——CVE-2024-0555—8.5%
——3——CVE-2026-3934—8.5%
——3——CVE-2026-25205—8.5%
——3——CVE-2025-23665—8.5%
——3——CVE-2013-1053—8.5%
——3——CVE-2024-2964—8.5%
——3——CVE-2025-34352—8.5%
——3——CVE-2023-20584—8.5%
——3——CVE-2023-25647—8.5%
——3——CVE-2019-14067—8.5%
——3——CVE-2024-502537.8 HIG8.5%
——3In the Linux kernel, the following vulnerability has been resolved:
bpf: Check the validity of nr_words in bpf_iter_bits_new()
Check the validity of nr_words in bpf_iter_bits_new(). Without this
check, when multiplication overflow occurs for nr_bits (e.g., when
nr_words = 0x0400-0001, nr_bits becomes 64), stack corruption may occur
due to bpf_probe_read_kernel_common(..., nr_bytes = 0x2000-0008).
Fix it by limiting the maximum value of nr_words to 511. The value is
derived from the current implementation of BPF memory allocator. To
ensure compatibility if the BPF memory allocator's size limitation
changes in the future, use the helper bpf_mem_alloc_check_size() to
check whether nr_bytes is too larger. And return -E2BIG instead of
-ENOMEM for oversized nr_bytes.5dCVE-2023-53336—8.5%
——3——CVE-2026-660056.3 MED8.5%
——3Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Attackers on the local network or using DNS rebinding can reach the unauthenticated OpenAI-compatible API to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses.10dCVE-2023-53339—8.5%
——3——CVE-2025-23660—8.5%
——3——CVE-2023-6573—8.5%
——3——CVE-2022-50357—8.5%
——3——CVE-2025-61762—8.5%
——3——CVE-2025-23662—8.5%
——3——CVE-2025-11013—8.5%
——3——CVE-2025-40193—8.5%
——3——CVE-2025-23577—8.5%
——3——CVE-2026-91237.5 HIG8.5%
——3Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium)17dCVE-2025-59967—8.5%
——3——