Vulnerabilities exploitable today
355,177in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,606
- High9,258
- Medium7,548
- Low695
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-54455—6.8%
——2——CVE-2026-48926—6.8%
——2——CVE-2023-20597—6.8%
——2——CVE-2024-45283—6.8%
——2——CVE-2025-14417—6.8%
——2——CVE-2022-50224—6.8%
——2——CVE-2024-22449—6.8%
——2——CVE-2025-55059—6.8%
——2——CVE-2025-39701—6.8%
——2——CVE-2025-38332—6.8%
——2——CVE-2026-53860—6.8%
——2——CVE-2025-68312—6.8%
——2——CVE-2023-21507—6.8%
——2——CVE-2025-3925—6.8%
——2——CVE-2019-9239—6.8%
——2——CVE-2026-31957.4 HIG6.8%
——2A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.20dCVE-2025-67543—6.7%
——2——CVE-2025-36728—6.7%
——2——CVE-2026-0165—6.7%
——2——CVE-2025-63037—6.7%
——2——CVE-2026-580285.4 MED6.7%
——2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation CentralAuth.
This vulnerability is associated with program files includes/Api/ApiFormatBase.Php, includes/Api/ApiHelp.Php, includes/ResourceLoader/Module.Php, includes/Hooks/Handlers/PageDisplayHookHandler.Php, includes/LogFormatter/PermissionChangeLogFormatter.Php.
This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9; CentralAuth: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.25dCVE-2025-47708—6.7%
——2——CVE-2023-39254—6.7%
——2——CVE-2023-0197—6.7%
——2——CVE-2026-142364.7 MED6.7%
——2The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.7dCVE-2022-48784—6.7%
——2——CVE-2017-18054—6.7%
——2——CVE-2017-18062—6.7%
——2——CVE-2024-3100—6.7%
——2——CVE-2025-0760—6.7%
——2——CVE-2023-31021—6.7%
——2——CVE-2023-31023—6.7%
——2——CVE-2022-36349—6.7%
——2——CVE-2025-0886—6.7%
——2——CVE-2025-40314—6.7%
——2——CVE-2023-25520—6.7%
——2——CVE-2025-378907.8 HIG6.7%
——2In the Linux kernel, the following vulnerability has been resolved:
net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc
As described in Gerrard's report [1], we have a UAF case when an hfsc class
has a netem child qdisc. The crux of the issue is that hfsc is assuming
that checking for cl->qdisc->q.qlen == 0 guarantees that it hasn't inserted
the class in the vttree or eltree (which is not true for the netem
duplicate case).
This patch checks the n_active class variable to make sure that the code
won't insert the class in the vttree or eltree twice, catering for the
reentrant case.
[1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/5dCVE-2017-18061—6.7%
——2——CVE-2023-30648—6.7%
——2——CVE-2025-40313—6.7%
——2——