Vulnerabilities exploitable today
355,017in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,558
- High9,191
- Medium7,449
- Low695
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1780—6.5%
——2——CVE-2026-40451—6.5%
——2——CVE-2023-28026—6.5%
——2——CVE-2023-25936—6.5%
——2——CVE-2025-68786—6.5%
——2——CVE-2024-8183—6.5%
——2——CVE-2023-32467—6.5%
——2——CVE-2023-28044—6.5%
——2——CVE-2025-22412—6.5%
——2——CVE-2024-27404—6.5%
——2——CVE-2026-66545.1 MED6.5%
——2Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.19dCVE-2020-0007—6.5%
——2——CVE-2025-68029—6.5%
——2——CVE-2025-20321—6.5%
——2——CVE-2025-68375—6.5%
——2——CVE-2025-14022—6.5%
——2——CVE-2023-28060—6.5%
——2——CVE-2022-48578—6.5%
——2——CVE-2023-28027—6.5%
——2——CVE-2025-22411—6.5%
——2——CVE-2025-43268—6.5%
——2——CVE-2022-20313—6.5%
——2——CVE-2022-31477—6.5%
——2——CVE-2024-56449—6.5%
——2——CVE-2024-371296.7 MED6.5%
——2Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.10dCVE-2025-60013—6.5%
——2——CVE-2026-125366.4 MED6.5%
——2The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ parameter in all versions up to, and including, 3.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.20dCVE-2022-20269—6.5%
——2——CVE-2026-0129—6.5%
——2——CVE-2025-9213—6.5%
——2——CVE-2026-129072.7 LOW6.5%
——2The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global areas displayed to all visitors, which is normally restricted to administrators.18dCVE-2023-28032—6.5%
——2——CVE-2026-27675—6.5%
——2——CVE-2025-71067—6.5%
——2——CVE-2026-3772—6.5%
——2——CVE-2022-29871—6.5%
——2——CVE-2020-0415—6.5%
——2——CVE-2023-28033—6.5%
——2——CVE-2023-25938—6.5%
——2——CVE-2018-253676.2 MED6.5%
——2NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field within the Geom browser pod addition interface.11d