Vulnerabilities exploitable today
356,684in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,538
- High10,642
- Medium6,744
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-4003—8.3%
——2——CVE-2026-25313—8.3%
——2——CVE-2025-4002—8.3%
——2——CVE-2024-4409—8.3%
——2——CVE-2022-1038—8.3%
——2——CVE-2026-15432—8.3%
——2When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the correct tag. This in turn could allow to find a correct tag bytewise.17dCVE-2026-25363—8.3%
——2——CVE-2025-43398—8.3%
——2——CVE-2019-2192—8.3%
——2——CVE-2026-28080—8.3%
——2——CVE-2022-50353—8.3%
——2——CVE-2026-25409—8.3%
——2——CVE-2025-21538—8.3%
——2——CVE-2026-2258—8.3%
——2——CVE-2023-53346—8.3%
——2——CVE-2026-64484—8.3%
——2In the Linux kernel, the following vulnerability has been resolved:
ALSA: es1938: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails.
snd_es1938_mixer() does not check the return value before dereferencing
the pointer, which can lead to a NULL pointer dereference.
Add a NULL check after snd_ctl_new1() and return -ENOMEM if it fails.15dCVE-2025-6232—8.3%
——2——CVE-2025-48329—8.3%
——2——CVE-2026-659136.1 MED8.3%
——2DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.11dCVE-2023-3363—8.3%
——2——CVE-2025-48241—8.3%
——2——CVE-2025-24258—8.3%
——2——CVE-2026-25402—8.3%
——2——CVE-2026-118724.3 MED8.3%
——2The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public navigation.3dCVE-2026-396534.3 MED8.3%
——2Missing Authorization vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Conferencing with Zoom: from n/a through <= 4.6.6.15dCVE-2025-48364—8.3%
——2——CVE-2026-556517.1 HIG8.3%
——2Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users.
Using these hashes, an attacker can modify or delete appointments of other providers, resulting in an Appointments Takeover. Version 1.6.0 fixes the issue.25dCVE-2026-254244.3 MED8.3%
——2Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.16dCVE-2024-31158—8.2%
——2——CVE-2025-47679—8.2%
——2——CVE-2024-4529—8.2%
——2——CVE-2025-36117—8.2%
——2——CVE-2025-9558—8.2%
——2——CVE-2026-73185.9 MED8.2%
——2A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic results in path traversal. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.16dCVE-2024-22095—8.2%
——2——CVE-2022-50928—8.2%
——2——CVE-2025-21769—8.2%
——2——CVE-2023-21439—8.2%
——2——CVE-2022-50571—8.2%
——2——CVE-2023-53706—8.2%
——2——