Vulnerabilities exploitable today
356,679in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,539
- High10,676
- Medium6,805
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-32889—8.0%
——2——CVE-2025-57891—8.0%
——2——CVE-2026-204575.3 MED8.0%
——2In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01826924; Issue ID: MSV-7301.38dCVE-2026-27512—8.0%
——2——CVE-2026-56310—8.0%
——2——CVE-2026-354746.1 MED8.0%
——2WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The redirect parameter is taken directly from $_GET with no URL validation or whitelist check, then used verbatim in a header("Location: ...") call. This vulnerability is fixed in 3.6.9.15dCVE-2025-46439—8.0%
——2——CVE-2026-23858—8.0%
——2——CVE-2025-54727—8.0%
——2——CVE-2025-68229—8.0%
——2——CVE-2018-25376—8.0%
——2——CVE-2026-47746—8.0%
——2Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. Because the JSON-LD parsing context is not shared between signature verification and subsequent processing, the application may trust information that should not be trusted, resulting in a time-of-check to time-of-use (TOCTOU) flaw. This allows an attacker to have fraudulent activities accepted as valid, leading to a loss of integrity. This issue has been fixed in version 2026.5.4.4dCVE-2025-66496—8.0%
——2——CVE-2026-133064.3 MED8.0%
——2Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the exposed USB interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-29046.9dCVE-2021-31839—8.0%
——2——CVE-2023-29414—8.0%
——2——CVE-2026-32452—8.0%
——2——CVE-2026-9084—8.0%
——2MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email ownership is not enforced, an attacker with a valid OIDC token could assert a victim’s email address and authenticate as that user, leading to account takeover.16dCVE-2023-540928.8 HIG8.0%
——2In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: pv: fix index value of replaced ASCE
The index field of the struct page corresponding to a guest ASCE should
be 0. When replacing the ASCE in s390_replace_asce(), the index of the
new ASCE should also be set to 0.
Having the wrong index might lead to the wrong addresses being passed
around when notifying pte invalidations, and eventually to validity
intercepts (VM crash) if the prefix gets unmapped and the notifier gets
called with the wrong address.4dCVE-2026-33143—8.0%
——2——CVE-2023-54086—8.0%
——2——CVE-2022-48226—8.0%
——2——CVE-2026-24672—8.0%
——2——CVE-2024-42153—8.0%
——2——CVE-2025-9194—8.0%
——2——CVE-2025-40222—8.0%
——2——CVE-2024-22382—8.0%
——2——CVE-2025-12156—8.0%
——2——CVE-2023-53342—8.0%
——2——CVE-2025-60473—8.0%
——2——CVE-2025-15412—8.0%
——2——CVE-2025-64379—8.0%
——2——CVE-2023-54105—8.0%
——2——CVE-2023-28399—8.0%
——2——CVE-2026-27440—8.0%
——2——CVE-2025-36057—8.0%
——2——CVE-2026-99855.3 MED8.0%
——2Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)18dCVE-2024-41063—8.0%
——2——CVE-2023-43089—8.0%
——2——CVE-2025-40227—8.0%
——2——