Vulnerabilities exploitable today
354,831in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,569
- High9,189
- Medium7,427
- Low692
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-12750—5.8%
——2——CVE-2026-140394.3 MED5.8%
——2Insufficient policy enforcement in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)30dCVE-2025-36537—5.8%
——2——CVE-2025-11795—5.8%
——2——CVE-2024-13438—5.8%
——2——CVE-2025-38113—5.8%
——2——CVE-2021-0322—5.8%
——2——CVE-2024-31202—5.8%
——2——CVE-2025-27402—5.8%
——2——CVE-2025-6974—5.8%
——2——CVE-2026-64167—5.8%
——2In the Linux kernel, the following vulnerability has been resolved:
kho: skip KHO for crash kernel
kho_fill_kimage() unconditionally populates the kimage with KHO
metadata for every kexec image type. When the image is a crash kernel,
this can be problematic as the crash kernel can run in a small reserved
region and the KHO scratch areas can sit outside it.
The crash kernel then faults during kho_memory_init() when it
tries phys_to_virt() on the KHO FDT address:
Unable to handle kernel paging request at virtual address xxxxxxxx
...
fdt_offset_ptr+...
fdt_check_node_offset_+...
fdt_first_property_offset+...
fdt_get_property_namelen_+...
fdt_getprop+...
kho_memory_init+...
mm_core_init+...
start_kernel+...
kho_locate_mem_hole() already skips KHO logic for KEXEC_TYPE_CRASH
images, but kho_fill_kimage() was missing the same guard. As
kho_fill_kimage() is the single point that populates image->kho.fdt
and image->kho.scratch, fixing it here is sufficient for both arm64
and x86 as the FDT and boot_params path are bailing out when these
fields are unset.2dCVE-2021-0996—5.8%
——2——CVE-2025-68138—5.8%
——2——CVE-2025-38056—5.8%
——2——CVE-2026-24228—5.8%
——2——CVE-2024-22374—5.8%
——2——CVE-2024-10581—5.8%
——2——CVE-2024-53100—5.8%
——2——CVE-2026-23874—5.8%
——2——CVE-2025-6946—5.8%
——2——CVE-2026-112146.5 MED5.8%
——2Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)10dCVE-2025-2954—5.7%
——2——CVE-2023-50900—5.7%
——2——CVE-2026-33570—5.7%
——2——CVE-2026-655226.5 MED5.7%
——2Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.10dCVE-2026-25465—5.7%
——2——CVE-2026-25307—5.7%
——2——CVE-2026-25432—5.7%
——2——CVE-2018-5898—5.7%
——2——CVE-2026-24952—5.7%
——2——CVE-2026-22463—5.7%
——2——CVE-2023-29495—5.7%
——2——CVE-2018-3579—5.7%
——2——CVE-2025-1223—5.7%
——2——CVE-2026-32521—5.7%
——2——CVE-2026-32352—5.7%
——2——CVE-2023-6450—5.7%
——2——CVE-2024-21828—5.7%
——2——CVE-2025-49511—5.7%
——2——CVE-2026-395176.5 MED5.7%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.6.8d