Vulnerabilities exploitable today
354,831in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,569
- High9,189
- Medium7,427
- Low692
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-6971—5.8%
——2——CVE-2025-68376—5.8%
——2——CVE-2023-20038—5.8%
——2——CVE-2024-56687—5.8%
——2——CVE-2025-59731—5.8%
——2——CVE-2026-42948—5.8%
——2——CVE-2026-25739—5.8%
——2——CVE-2022-32570—5.8%
——2——CVE-2025-7042—5.8%
——2——CVE-2023-54035—5.8%
——2——CVE-2025-68729—5.8%
——2——CVE-2024-24782—5.8%
——2——CVE-2022-50412—5.8%
——2——CVE-2021-39648—5.8%
——2——CVE-2025-29720—5.8%
——2——CVE-2024-10677—5.8%
——2——CVE-2023-52590—5.8%
——2——CVE-2026-178786.1 MED5.8%
——2Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)2dCVE-2024-50294—5.8%
——2——CVE-2025-38122—5.8%
——2——CVE-2025-64145—5.8%
——2——CVE-2022-50020—5.8%
——2——CVE-2025-38020—5.8%
——2——CVE-2025-20275—5.8%
——2——CVE-2026-64244—5.8%
——2In the Linux kernel, the following vulnerability has been resolved:
drivers/base/memory: set mem->altmap after successful device registration
If __add_memory_block() fails at xa_store() (under memory pressure for
example), device_unregister() is called, which eventually triggers
memory_block_release() with mem->altmap still set, causing a
WARN_ON(mem->altmap). This was triggered by modifying virtio-mem driver.
Fix this by delaying the assignment of mem->altmap until after
__add_memory_block() has succeeded.2dCVE-2026-528429.3 CRI5.8%
——2Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority component when computing a page origin, so a URL such as `http://attacker.com/@victim.com/` was fetched from attacker.com but treated as `http://victim.com`, allowing a complete Same-Origin Policy bypass. This issue is fixed in version 0.3.1.17dCVE-2026-558085.4 MED5.8%
——2Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.16dCVE-2023-54027—5.8%
——2——CVE-2022-50026—5.8%
——2——CVE-2024-11373—5.8%
——2——CVE-2024-21806—5.8%
——2——CVE-2026-6777—5.8%
——2——CVE-2025-64144—5.8%
——2——CVE-2024-51630—5.8%
——2——CVE-2022-36372—5.8%
——2——CVE-2025-6972—5.8%
——2——CVE-2023-54324—5.8%
——2——CVE-2024-47668—5.8%
——2——CVE-2026-40529—5.8%
——2——CVE-2023-32476—5.8%
——2——