Vulnerabilities exploitable today
354,756in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,586
- High9,230
- Medium7,495
- Low701
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-43634—5.6%
——2——CVE-2025-21933—5.6%
——2——CVE-2025-12067—5.6%
——2——CVE-2026-24376.4 MED5.6%
——2The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.8dCVE-2025-60181—5.6%
——2——CVE-2026-642847.1 HIG5.6%
——2In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits
Move the handling of fastpath userspace exits into vendor code to ensure
KVM runs vendor specific operations that need to run before userspace gains
control of the vCPU. E.g. for VMX (and soon to be for SVM as well), KVM
needs to flush the PML buffer prior to exiting to userspace, otherwise any
memory written by the final KVM_RUN might never be flagged as dirty.
Note, waiting to snapshot CR0 and CR3 until svm_handle_exit() is flawed in
general, as that risks consuming stale state in a fastpath handler. That
will be addressed in a future change.2dCVE-2025-25727—5.6%
——2——CVE-2025-23281—5.6%
——2——CVE-2021-30334—5.6%
——2——CVE-2025-32058—5.6%
——2——CVE-2021-35130—5.6%
——2——CVE-2026-112914.3 MED5.6%
——2Inappropriate implementation in Android Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)9dCVE-2026-20990—5.6%
——2——CVE-2021-22398—5.6%
——2——CVE-2020-25280—5.6%
——2——CVE-2026-1574—5.6%
——2——CVE-2024-22016—5.6%
——2——CVE-2026-45925—5.6%
——2——CVE-2021-1913—5.6%
——2——CVE-2024-54683—5.6%
——2——CVE-2026-45858—5.6%
——2——CVE-2021-25430—5.6%
——2——CVE-2026-132416.5 MED5.6%
——2Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.11dCVE-2023-30707—5.6%
——2——CVE-2021-35091—5.6%
——2——CVE-2026-132396.5 MED5.6%
——2Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from 0.0.0 to 4.2.0.19dCVE-2025-71107—5.6%
——2——CVE-2026-33793—5.6%
——2——CVE-2025-380807.8 HIG5.6%
——2In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Increase block_sequence array size
[Why]
It's possible to generate more than 50 steps in hwss_build_fast_sequence,
for example with a 6-pipe asic where all pipes are in one MPC chain. This
overflows the block_sequence buffer and corrupts block_sequence_steps,
causing a crash.
[How]
Expand block_sequence to 100 items. A naive upper bound on the possible
number of steps for a 6-pipe asic, ignoring the potential for steps to be
mutually exclusive, is 91 with current code, therefore 100 is sufficient.2dCVE-2002-1739—5.6%
——2——CVE-2019-256568.4 HIG5.6%
——2R i386 3.5.0 contains a local buffer overflow vulnerability in the GUI Preferences dialog that allows local attackers to trigger a structured exception handler (SEH) overwrite by supplying malicious input. Attackers can craft a payload string in the 'Language for menus and messages' field to overwrite SEH records and achieve code execution with calculator or arbitrary shellcode.8dCVE-2026-46000—5.6%
——2——CVE-2026-3437—5.6%
——2——CVE-2026-26230—5.6%
——2——CVE-2024-48828—5.6%
——2——CVE-2025-8383—5.6%
——2——CVE-2025-58641—5.6%
——2——CVE-2025-385737.3 HIG5.6%
——2In the Linux kernel, the following vulnerability has been resolved:
spi: cs42l43: Property entry should be a null-terminated array
The software node does not specify a count of property entries, so the
array must be null-terminated.
When unterminated, this can lead to a fault in the downstream cs35l56
amplifier driver, because the node parse walks off the end of the
array into unknown memory.2dCVE-2026-467288.2 HIG5.6%
——2Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.18dCVE-2017-11035—5.6%
——2——