Vulnerabilities exploitable today
354,831in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,554
- High9,165
- Medium7,426
- Low692
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-11195—5.8%
——2——CVE-2023-54204—5.8%
——2——CVE-2025-14262—5.8%
——2——CVE-2025-701005.5 MED5.8%
——2A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size.10dCVE-2022-50852—5.8%
——2——CVE-2020-11194—5.8%
——2——CVE-2023-53127—5.8%
——2——CVE-2023-7261—5.8%
——2——CVE-2026-27284—5.8%
——2——CVE-2026-12635—5.8%
——2——CVE-2016-200515.3 MED5.8%
——2Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup action, modifying the admin username and password parameters to gain unauthorized access.12dCVE-2023-54075—5.8%
——2——CVE-2024-10031—5.8%
——2——CVE-2025-38007—5.8%
——2——CVE-2023-32461—5.8%
——2——CVE-2022-50862—5.8%
——2——CVE-2025-68196—5.8%
——2——CVE-2025-68228—5.8%
——2——CVE-2023-54165—5.8%
——2——CVE-2026-64179—5.8%
——2In the Linux kernel, the following vulnerability has been resolved:
net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
The memory allocated in ipc_protocol_init() is not freed on the error
paths that follow in ipc_imem_init(). Fix that by calling the
corresponding release function ipc_protocol_deinit() in the error path.3dCVE-2019-9290—5.8%
——2——CVE-2020-11606—5.8%
——2——CVE-2023-54174—5.8%
——2——CVE-2022-47451—5.8%
——2——CVE-2026-95723.3 LOW5.8%
——2A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of the argument cat leads to memory leak. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The name of the patch is e79c5cbe8b3fed27f4854ec229457d30c96206f1. It is best practice to apply a patch to resolve this issue.10dCVE-2025-68169—5.8%
——2——CVE-2024-49387—5.8%
——2——CVE-2025-40355—5.8%
——2——CVE-2026-27841—5.8%
——2——CVE-2020-11271—5.8%
——2——CVE-2023-54273—5.8%
——2——CVE-2023-54070—5.8%
——2——CVE-2025-68209—5.8%
——2——CVE-2024-38282—5.8%
——2——CVE-2024-25959—5.8%
——2——CVE-2022-49911—5.8%
——2——CVE-2020-11187—5.8%
——2——CVE-2026-150855.4 MED5.8%
——2Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3.19dCVE-2025-68197—5.8%
——2——CVE-2023-54223—5.8%
——2——