Vulnerabilities exploitable today
356,659in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,528
- High10,661
- Medium6,811
- Low680
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-37786—8.0%
——2——CVE-2023-39984—8.0%
——2——CVE-2025-12038—8.0%
——2——CVE-2022-27500—8.0%
——2——CVE-2023-54138—8.0%
——2——CVE-2025-31162—8.0%
——2——CVE-2025-40247—8.0%
——2——CVE-2025-14290—8.0%
——2——CVE-2024-28951—8.0%
——2——CVE-2025-11172—8.0%
——2——CVE-2020-0110—8.0%
——2——CVE-2025-40255—8.0%
——2——CVE-2023-39985—8.0%
——2——CVE-2023-54131—8.0%
——2——CVE-2025-40229—8.0%
——2——CVE-2023-21395—8.0%
——2——CVE-2025-12563—8.0%
——2——CVE-2024-26999—8.0%
——2——CVE-2025-40232—8.0%
——2——CVE-2026-449036.1 MED8.0%
——2Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram heatmap chart view does not escape le label values when inserting them into the HTML for use as axis tick mark labels. An attacker who can inject crafted metrics can execute JavaScript in the browser of any Prometheus user who views the metric in the heatmap chart UI. This vulnerability is fixed in 3.5.3 and 3.11.3.15dCVE-2025-21551—8.0%
——2——CVE-2025-60251—8.0%
——2——CVE-2026-18243—8.0%
——2Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.5dCVE-2023-54118—8.0%
——2——CVE-2025-40224—8.0%
——2——CVE-2026-169704.2 MED8.0%
——2The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.4dCVE-2023-525177.8 HIG8.0%
——2In the Linux kernel, the following vulnerability has been resolved:
spi: sun6i: fix race between DMA RX transfer completion and RX FIFO drain
Previously the transfer complete IRQ immediately drained to RX FIFO to
read any data remaining in FIFO to the RX buffer. This behaviour is
correct when dealing with SPI in interrupt mode. However in DMA mode the
transfer complete interrupt still fires as soon as all bytes to be
transferred have been stored in the FIFO. At that point data in the FIFO
still needs to be picked up by the DMA engine. Thus the drain procedure
and DMA engine end up racing to read from RX FIFO, corrupting any data
read. Additionally the RX buffer pointer is never adjusted according to
DMA progress in DMA mode, thus calling the RX FIFO drain procedure in DMA
mode is a bug.
Fix corruptions in DMA RX mode by draining RX FIFO only in interrupt mode.
Also wait for completion of RX DMA when in DMA mode before returning to
ensure all data has been copied to the supplied memory buffer.4dCVE-2023-54101—8.0%
——2——CVE-2022-50648—8.0%
——2——CVE-2022-4994—8.0%
——2In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: wean fast IN from emulator_pio_in
Use __emulator_pio_in() directly for fast PIO instead of bouncing through
emulator_pio_in() now that __emulator_pio_in() fills "val" when handling
in-kernel PIO. vcpu->arch.pio.count is guaranteed to be '0', so this a
pure nop.
emulator_pio_in_emulated is now the last caller of emulator_pio_in.
No functional change intended.9dCVE-2023-53791—8.0%
——2——CVE-2025-22246—8.0%
——2——CVE-2025-24742—8.0%
——2——CVE-2025-38326—8.0%
——2——CVE-2026-157824.9 MED8.0%
——2The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.18dCVE-2023-54192—8.0%
——2——CVE-2024-39442—8.0%
——2——CVE-2026-24665—8.0%
——2——CVE-2022-29507—8.0%
——2——CVE-2025-67427—8.0%
——2——