Vulnerabilities exploitable today
355,082in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,578
- High9,224
- Medium7,476
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-45853—6.6%
——2——CVE-2025-64517—6.6%
——2——CVE-2025-38131—6.6%
——2——CVE-2025-15417—6.6%
——2——CVE-2024-47978—6.6%
——2——CVE-2026-45210—6.6%
——2——CVE-2019-2049—6.6%
——2——CVE-2024-56771—6.6%
——2——CVE-2025-69341—6.6%
——2——CVE-2024-55641—6.6%
——2——CVE-2019-13762—6.6%
——2——CVE-2026-34640—6.6%
——2——CVE-2025-69349—6.6%
——2——CVE-2024-56368—6.6%
——2——CVE-2026-177615.4 MED6.6%
——2Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)3dCVE-2026-2403—6.6%
——2——CVE-2025-4211—6.6%
——2Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024-38081. The vulnerability arises from the use of the GetTempPath API, which can be exploited by attackers to manipulate temporary file paths, potentially leading to unauthorized access and privilege escalation. The affected public API in the Qt Framework is QDir::tempPath() and anything that uses it, such as QStandardPaths with TempLocation, QTemporaryDir, and QTemporaryFile.
This issue affects all version of Qt up to and including 5.15.18, from 6.0.0 through 6.5.8, from 6.6.0 through 6.8.1. It is fixed in Qt 5.15.19, Qt 6.5.9, Qt 6.8.2, 6.9.05dCVE-2022-50085—6.6%
——2——CVE-2025-380977.8 HIG6.6%
——2In the Linux kernel, the following vulnerability has been resolved:
espintcp: remove encap socket caching to avoid reference leak
The current scheme for caching the encap socket can lead to reference
leaks when we try to delete the netns.
The reference chain is: xfrm_state -> enacp_sk -> netns
Since the encap socket is a userspace socket, it holds a reference on
the netns. If we delete the espintcp state (through flush or
individual delete) before removing the netns, the reference on the
socket is dropped and the netns is correctly deleted. Otherwise, the
netns may not be reachable anymore (if all processes within the ns
have terminated), so we cannot delete the xfrm state to drop its
reference on the socket.
This patch results in a small (~2% in my tests) performance
regression.
A GC-type mechanism could be added for the socket cache, to clear
references if the state hasn't been used "recently", but it's a lot
more complex than just not caching the socket.5dCVE-2026-24990—6.6%
——2——CVE-2025-15418—6.6%
——2——CVE-2026-242377.8 HIG6.6%
——2NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.12dCVE-2025-1738—6.6%
——2——CVE-2025-38072—6.6%
——2——CVE-2026-134325.4 MED6.6%
——2The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality.14dCVE-2022-20524—6.6%
——2——CVE-2026-15243—6.6%
——2Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate for a hostname that matches the configured allowlist or regex. This can lead to intercepting the CAS exchange, capturing the Ticket-Granting Ticket (TGT), and subsequently obtaining Service Tickets on behalf of the victim.
Because maintainers contact attempts were unsuccessful, vulnerabilities have only been confirmed in version 4.1.0 (Java Apereo CAS Client) and 3.6.4 (Jasig CAS Client) but may also affect other versions.4dCVE-2024-23800—6.6%
——2——CVE-2026-39943—6.6%
——2——CVE-2026-24622—6.6%
——2——CVE-2026-12058—6.6%
——2——CVE-2024-39442—6.6%
——2——CVE-2026-34094—6.6%
——2——CVE-2025-38143—6.6%
——2——CVE-2023-43591—6.6%
——2——CVE-2026-578517.8 HIG6.6%
——2MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.24dCVE-2019-25559—6.6%
——2——CVE-2025-12986—6.6%
——2——CVE-2019-2127—6.6%
——2——CVE-2024-57839—6.6%
——2——