Vulnerabilities exploitable today
355,082in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,578
- High9,224
- Medium7,476
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-123965.4 MED6.6%
——2The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary jobs, including those owned by other users.21dCVE-2023-53362—6.6%
——2——CVE-2026-58926.6 MED6.6%
——2Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to install a PWA without user consent via a crafted HTML page. (Chromium security severity: Medium)10dCVE-2019-2096—6.6%
——2——CVE-2026-47222—6.6%
——2——CVE-2025-20003—6.6%
——2——CVE-2025-15418—6.6%
——2——CVE-2026-34094—6.6%
——2——CVE-2026-24622—6.6%
——2——CVE-2026-242377.8 HIG6.6%
——2NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.12dCVE-2026-24990—6.6%
——2——CVE-2024-39442—6.6%
——2——CVE-2026-12058—6.6%
——2——CVE-2025-38143—6.6%
——2——CVE-2026-39943—6.6%
——2——CVE-2025-26963—6.6%
——2——CVE-2026-25021—6.6%
——2——CVE-2024-57799—6.6%
——2——CVE-2019-13762—6.6%
——2——CVE-2025-30598—6.6%
——2——CVE-2025-30421—6.6%
——2——CVE-2025-12761—6.6%
——2——CVE-2025-26662—6.6%
——2——CVE-2026-25473—6.6%
——2——CVE-2024-57914—6.6%
——2——CVE-2026-31412—6.6%
——2——CVE-2024-57839—6.6%
——2——CVE-2025-38009—6.6%
——2——CVE-2019-2336—6.6%
——2——CVE-2025-68479—6.6%
——2——CVE-2024-38724—6.6%
——2——CVE-2026-619585.4 MED6.6%
——2Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.21dCVE-2023-20516—6.6%
——2——CVE-2022-23236—6.6%
——2——CVE-2020-0305—6.6%
——2——CVE-2026-2403—6.6%
——2——CVE-2022-50085—6.6%
——2——CVE-2025-380977.8 HIG6.6%
——2In the Linux kernel, the following vulnerability has been resolved:
espintcp: remove encap socket caching to avoid reference leak
The current scheme for caching the encap socket can lead to reference
leaks when we try to delete the netns.
The reference chain is: xfrm_state -> enacp_sk -> netns
Since the encap socket is a userspace socket, it holds a reference on
the netns. If we delete the espintcp state (through flush or
individual delete) before removing the netns, the reference on the
socket is dropped and the netns is correctly deleted. Otherwise, the
netns may not be reachable anymore (if all processes within the ns
have terminated), so we cannot delete the xfrm state to drop its
reference on the socket.
This patch results in a small (~2% in my tests) performance
regression.
A GC-type mechanism could be added for the socket cache, to clear
references if the state hasn't been used "recently", but it's a lot
more complex than just not caching the socket.4dCVE-2019-10535—6.6%
——2——CVE-2026-177615.4 MED6.6%
——2Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)3d