Vulnerabilities exploitable today
356,426in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603
Distribution · last window
- Critical2,802
- High11,190
- Medium7,403
- Low703
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-5673—7.5%
——2——CVE-2021-26354—7.5%
——2——CVE-2025-1269—7.5%
——2——CVE-2024-43107—7.5%
——2——CVE-2024-40771—7.5%
——2——CVE-2026-4121—7.5%
——2——CVE-2025-59261—7.5%
——2——CVE-2024-48291—7.5%
——2——CVE-2026-272225.5 MED7.5%
——2Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or render it unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.17dCVE-2023-21430—7.5%
——2——CVE-2017-2739—7.5%
——2——CVE-2024-53809—7.5%
——2——CVE-2026-28726—7.5%
——2——CVE-2024-28829—7.5%
——2——CVE-2026-8001—7.5%
——2——CVE-2025-40766—7.5%
——2——CVE-2025-36037—7.5%
——2——CVE-2026-179366.5 MED7.5%
——2Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)4dCVE-2025-64196—7.5%
——2——CVE-2026-1228—7.5%
——2——CVE-2025-53307—7.5%
——2——CVE-2022-22424—7.5%
——2——CVE-2024-12530—7.5%
——2——CVE-2025-52555—7.5%
——2——CVE-2026-31850—7.5%
——2——CVE-2019-25571—7.5%
——2——CVE-2025-43744—7.5%
——2——CVE-2024-56251—7.5%
——2——CVE-2024-38613—7.5%
——2——CVE-2025-12820—7.5%
——2——CVE-2026-470883.1 LOW7.5%
——2An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user.21dCVE-2025-4532—7.5%
——2——CVE-2026-575305.4 MED7.5%
——2Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The parseMarkdown runner stores raw URL values from the remark AST as href mark attributes without URL scheme validation, and the ineffective DOMPurify.sanitize call in edit-view.ts treats the bare URL string as a text node and returns it unchanged, allowing javascript: payloads to pass through the link-tooltip preview component and read-only mode anchor elements unmodified.10dCVE-2026-9653—7.5%
——2A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.24dCVE-2025-231315.5 MED7.5%
——2In the Linux kernel, the following vulnerability has been resolved:
dlm: prevent NPD when writing a positive value to event_done
do_uevent returns the value written to event_done. In case it is a
positive value, new_lockspace would undo all the work, and lockspace
would not be set. __dlm_new_lockspace, however, would treat that
positive value as a success due to commit 8511a2728ab8 ("dlm: fix use
count with multiple joins").
Down the line, device_create_lockspace would pass that NULL lockspace to
dlm_find_lockspace_local, leading to a NULL pointer dereference.
Treating such positive values as successes prevents the problem. Given
this has been broken for so long, this is unlikely to break userspace
expectations.34dCVE-2025-64224—7.5%
——2——CVE-2026-225695.4 MED7.5%
——2An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.13dCVE-2024-37237—7.5%
——2——CVE-2026-119015.3 MED7.5%
——2The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal validation endpoint from the attacker-controlled `$_REQUEST['test_ipn']` parameter, force-upgrading any `pending` transaction to `completed` when `test_ipn=1`, and omitting post-verification checks on `receiver_email`, `mc_currency`, and `txn_id` uniqueness after receiving a `VERIFIED` response from PayPal. This makes it possible for unauthenticated attackers to mark arbitrary hotel bookings as fully paid without submitting genuine payment to the merchant — either by routing IPN validation through PayPal's sandbox using a free sandbox account, or by replaying a previously verified IPN from a nominal payment to an attacker-controlled PayPal account. An attacker requires only a free PayPal sandbox account (or any PayPal account) to obtain a `VERIFIED` response; no site credentials or special configuration are needed.24dCVE-2025-37805—7.5%
——2——