Vulnerabilities exploitable today
355,082in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,577
- High9,224
- Medium7,474
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-53587—6.7%
——2——CVE-2025-54747—6.7%
——2——CVE-2026-14841—6.7%
——2The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricked into loading a crafted page.2dCVE-2020-37079—6.7%
——2——CVE-2026-41526—6.7%
——2——CVE-2024-37997—6.7%
——2——CVE-2024-21455—6.7%
——2——CVE-2026-601195.4 MED6.7%
——2Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by embedding a malicious event title containing the </script> sequence, which is not escaped by JSON.stringify() when embedded in inline script tags. Attackers can craft an event title that breaks out of the script context in the application/ld+json structured data block or server-side rehydrated state, causing the payload to execute in the browser of any user who views the public event page, including unauthenticated visitors and authenticated administrators.19dCVE-2024-42294—6.7%
——2——CVE-2025-52825—6.7%
——2——CVE-2025-60179—6.7%
——2——CVE-2024-20886—6.7%
——2——CVE-2025-2896—6.7%
——2——CVE-2026-483407.8 HIG6.7%
——2Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.18dCVE-2024-47143—6.7%
——2——CVE-2025-42915—6.7%
——2——CVE-2024-42912—6.7%
——2——CVE-2024-51157—6.7%
——2——CVE-2018-5888—6.7%
——2——CVE-2024-23801—6.7%
——2——CVE-2023-44213—6.7%
——2——CVE-2025-9068—6.7%
——2——CVE-2023-42958—6.7%
——2——CVE-2024-13304—6.7%
——2——CVE-2025-14456—6.7%
——2——CVE-2025-47127—6.7%
——2——CVE-2025-31244—6.7%
——2——CVE-2025-5963—6.7%
——2——CVE-2019-2033—6.7%
——2——CVE-2025-384987.8 HIG6.7%
——2In the Linux kernel, the following vulnerability has been resolved:
do_change_type(): refuse to operate on unmounted/not ours mounts
Ensure that propagation settings can only be changed for mounts located
in the caller's mount namespace. This change aligns permission checking
with the rest of mount(2).5dCVE-2026-122734.3 MED6.7%
——2The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post auto-approved comments containing arbitrary HTML and links on any content across the site, bypassing the comment moderation queue.21dCVE-2026-119807.3 HIG6.7%
——2IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.3dCVE-2021-1969—6.7%
——2——CVE-2025-30601—6.7%
——2——CVE-2024-12636—6.7%
——2——CVE-2025-54390—6.7%
——2——CVE-2025-64291—6.7%
——2——CVE-2025-60982—6.7%
——2——CVE-2025-58886—6.7%
——2——CVE-2026-3565—6.7%
——2——