Vulnerabilities exploitable today
356,659in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,537
- High10,684
- Medium6,859
- Low685
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-13895—7.9%
——2——CVE-2025-7659—7.9%
——2——CVE-2019-9454—7.9%
——2——CVE-2026-500896.1 MED7.9%
——2The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (6.1 Medium), which can be used to set up a phishing attack.30dCVE-2025-4423—7.9%
——2——CVE-2022-49748—7.9%
——2——CVE-2025-4422—7.9%
——2——CVE-2024-42242—7.9%
——2——CVE-2026-112604.3 MED7.9%
——2Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)16dCVE-2026-4056—7.9%
——2——CVE-2022-43701—7.9%
——2——CVE-2022-49749—7.9%
——2——CVE-2020-37127—7.9%
——2——CVE-2025-14836—7.9%
——2——CVE-2025-8681—7.9%
——2——CVE-2026-136925.3 MED7.9%
——2The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.9dCVE-2025-22011—7.9%
——2——CVE-2026-57665—7.9%
——2——CVE-2025-23278—7.9%
——2——CVE-2026-6277—7.9%
——2——CVE-2026-88416.4 MED7.9%
——2The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribute in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping in the rxstg_shortcode() function, which concatenates the user-supplied 'title' attribute directly into HTML output. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.16dCVE-2025-378007.1 HIG7.9%
——2In the Linux kernel, the following vulnerability has been resolved:
driver core: fix potential NULL pointer dereference in dev_uevent()
If userspace reads "uevent" device attribute at the same time as another
threads unbinds the device from its driver, change to dev->driver from a
valid pointer to NULL may result in crash. Fix this by using READ_ONCE()
when fetching the pointer, and take bus' drivers klist lock to make sure
driver instance will not disappear while we access it.
Use WRITE_ONCE() when setting the driver pointer to ensure there is no
tearing.9dCVE-2026-35255—7.9%
——2——CVE-2025-672916.1 MED7.9%
——2A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.35dCVE-2024-44147—7.9%
——2——CVE-2023-53010—7.9%
——2——CVE-2023-31413—7.9%
——2——CVE-2026-204826.5 MED7.9%
——2In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.5dCVE-2022-26062—7.9%
——2——CVE-2024-34490—7.9%
——2——CVE-2024-43299—7.9%
——2——CVE-2026-99948.3 HIG7.9%
——2Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)18dCVE-2026-48943—7.9%
——2——CVE-2026-0747—7.9%
——2——CVE-2015-20113—7.9%
——2——CVE-2026-8039—7.9%
——2——CVE-2023-28469—7.9%
——2——CVE-2025-14283—7.9%
——2——CVE-2026-31821—7.9%
——2——CVE-2026-8566—7.9%
——2——