Vulnerabilities exploitable today
354,756in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,607
- High9,344
- Medium7,588
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-11143—5.5%
——2——CVE-2024-12572—5.5%
——2——CVE-2025-38183—5.5%
——2——CVE-2021-35080—5.5%
——2——CVE-2026-32107—5.5%
——2——CVE-2024-11812—5.5%
——2——CVE-2024-37996—5.5%
——2——CVE-2026-162164.3 MED5.5%
——2A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.11dCVE-2026-396706.0 MED5.5%
——2Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request Forgery.This issue affects Visual Link Preview: from n/a through <= 2.3.0.8dCVE-2024-46462—5.5%
——2——CVE-2026-178677.1 HIG5.5%
——2Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)2dCVE-2024-7984—5.5%
——2——CVE-2024-46463—5.5%
——2——CVE-2026-177814.3 MED5.5%
——2Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)2dCVE-2026-21343—5.5%
——2——CVE-2026-366134.3 MED5.5%
——2Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POST requests to undefined paths, exposing server state to unauthenticated adjacent network attackers.10dCVE-2026-164155.4 MED5.5%
——2Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)8dCVE-2026-567435.4 MED5.5%
——2Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.15dCVE-2025-23113—5.5%
——2——CVE-2025-13097—5.5%
——2——CVE-2021-30338—5.5%
——2——CVE-2022-20433—5.5%
——2——CVE-2025-24375—5.5%
——2——CVE-2026-40941—5.5%
——2——CVE-2025-38134—5.5%
——2——CVE-2026-6411—5.5%
——2——CVE-2026-65893—5.5%
——2This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware.
An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.5dCVE-2023-32477—5.5%
——2——CVE-2024-8082—5.5%
——2——CVE-2025-0610—5.5%
——2——CVE-2026-27673—5.5%
——2——CVE-2026-148004.3 MED5.5%
——2A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.26dCVE-2026-483648.2 HIG5.5%
——2ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.17dCVE-2025-59347—5.5%
——2——CVE-2025-13606—5.5%
——2——CVE-2021-1909—5.5%
——2——CVE-2025-31256—5.5%
——2——CVE-2026-1076—5.5%
——2——CVE-2026-32884—5.5%
——2——CVE-2026-1070—5.5%
——2——