Vulnerabilities exploitable today
354,953in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,556
- High9,179
- Medium7,436
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-20942—6.5%
——2——CVE-2025-12832—6.5%
——2——CVE-2026-7260—6.5%
——2Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.4dCVE-2025-61859—6.5%
——2——CVE-2022-50434—6.5%
——2——CVE-2022-36439—6.5%
——2——CVE-2026-396455.4 MED6.5%
——2Server-Side Request Forgery (SSRF) vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommerce allows Server Side Request Forgery.This issue affects GlobalPayments WooCommerce: from n/a through <= 1.18.0.10dCVE-2016-20086—6.5%
——2——CVE-2026-41906—6.5%
——2——CVE-2025-36131—6.5%
——2——CVE-2023-29080—6.5%
——2——CVE-2025-57699—6.5%
——2——CVE-2019-20591—6.5%
——2——CVE-2022-20491—6.5%
——2——CVE-2018-3570—6.5%
——2——CVE-2022-50084—6.5%
——2——CVE-2025-30588—6.5%
——2——CVE-2024-52062—6.5%
——2——CVE-2026-12323—6.5%
——2——CVE-2026-492038.3 HIG6.5%
——2Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.12dCVE-2026-425996.1 MED6.5%
——2Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. Note that this vulnerability only triggers if the user's browser has JavaScript enabled but Svelte's hydration mechanism does not reach the vulnerable element before the event fires. This issue has been patched in version 5.55.7.11dCVE-2023-28714—6.5%
——2——CVE-2025-67876—6.5%
——2——CVE-2023-46183—6.5%
——2——CVE-2016-20085—6.5%
——2——CVE-2024-47797—6.5%
——2——CVE-2024-36066—6.5%
——2——CVE-2025-12286—6.5%
——2——CVE-2026-112664.3 MED6.5%
——2Inappropriate implementation in SafeBrowsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass Safe Browsing via a malicious file. (Chromium security severity: Low)11dCVE-2026-46894—6.5%
——2——CVE-2025-30586—6.5%
——2——CVE-2026-132374.8 MED6.5%
——2Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.18dCVE-2026-579544.3 MED6.5%
——2Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative field ordering across all rows via both JSON:API and GraphQL read paths.34dCVE-2025-62674—6.5%
——2——CVE-2023-27391—6.5%
——2——CVE-2021-41208—6.5%
——2——CVE-2026-348066.4 MED6.5%
——2Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/snat.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.10dCVE-2025-54866—6.5%
——2——CVE-2025-385397.8 HIG6.5%
——2In the Linux kernel, the following vulnerability has been resolved:
tracing: Add down_write(trace_event_sem) when adding trace event
When a module is loaded, it adds trace events defined by the module. It
may also need to modify the modules trace printk formats to replace enum
names with their values.
If two modules are loaded at the same time, the adding of the event to the
ftrace_events list can corrupt the walking of the list in the code that is
modifying the printk format strings and crash the kernel.
The addition of the event should take the trace_event_sem for write while
it adds the new event.
Also add a lockdep_assert_held() on that semaphore in
__trace_add_event_dirs() as it iterates the list.4dCVE-2022-20479—6.5%
——2——