Vulnerabilities exploitable today
355,082in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,577
- High9,224
- Medium7,474
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-43064—6.7%
——2——CVE-2025-64729—6.7%
——2——CVE-2025-63055—6.7%
——2——CVE-2026-579525.3 MED6.7%
——2Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verify payload ownership. An operator in one operation can invoke these endpoints with a known payload UUID from another operation to access that operation's C2 profile configuration including encryption keys and callback parameters.20dCVE-2025-67549—6.7%
——2——CVE-2024-40810—6.7%
——2——CVE-2023-0200—6.7%
——2——CVE-2025-47701—6.7%
——2——CVE-2025-40313—6.7%
——2——CVE-2023-31023—6.7%
——2——CVE-2024-3100—6.7%
——2——CVE-2023-31021—6.7%
——2——CVE-2017-18061—6.7%
——2——CVE-2025-378907.8 HIG6.7%
——2In the Linux kernel, the following vulnerability has been resolved:
net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc
As described in Gerrard's report [1], we have a UAF case when an hfsc class
has a netem child qdisc. The crux of the issue is that hfsc is assuming
that checking for cl->qdisc->q.qlen == 0 guarantees that it hasn't inserted
the class in the vttree or eltree (which is not true for the netem
duplicate case).
This patch checks the n_active class variable to make sure that the code
won't insert the class in the vttree or eltree twice, catering for the
reentrant case.
[1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/5dCVE-2025-40314—6.7%
——2——CVE-2025-36728—6.7%
——2——CVE-2025-0760—6.7%
——2——CVE-2025-63037—6.7%
——2——CVE-2017-18062—6.7%
——2——CVE-2025-47708—6.7%
——2——CVE-2026-142364.7 MED6.7%
——2The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.7dCVE-2022-36349—6.7%
——2——CVE-2017-18054—6.7%
——2——CVE-2025-0886—6.7%
——2——CVE-2026-0165—6.7%
——2——CVE-2022-48784—6.7%
——2——CVE-2026-580285.4 MED6.7%
——2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation CentralAuth.
This vulnerability is associated with program files includes/Api/ApiFormatBase.Php, includes/Api/ApiHelp.Php, includes/ResourceLoader/Module.Php, includes/Hooks/Handlers/PageDisplayHookHandler.Php, includes/LogFormatter/PermissionChangeLogFormatter.Php.
This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9; CentralAuth: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.25dCVE-2025-67543—6.7%
——2——CVE-2023-0197—6.7%
——2——CVE-2023-39254—6.7%
——2——CVE-2019-5246—6.7%
——2——CVE-2024-4018—6.7%
——2——CVE-2025-63052—6.7%
——2——CVE-2024-4017—6.7%
——2——CVE-2023-53754—6.7%
——2——CVE-2023-53761—6.7%
——2——CVE-2026-50099—6.7%
——2——CVE-2026-437534.6 MED6.7%
——2An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sensitive user information.6dCVE-2025-66105—6.7%
——2——CVE-2026-0513—6.7%
——2——