Vulnerabilities exploitable today
354,689in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,617
- High9,375
- Medium7,592
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-64750—5.3%
——2——CVE-2020-0389—5.3%
——2——CVE-2025-31482—5.3%
——2——CVE-2026-271738.7 HIG5.3%
——2JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.30dCVE-2021-22366—5.3%
——2——CVE-2025-12875—5.3%
——2——CVE-2025-1362—5.3%
——2——CVE-2026-64511—5.3%
——2In the Linux kernel, the following vulnerability has been resolved:
ACPI: NFIT: core: Fix possible NULL pointer dereference
After commit 9b311b7313d6 ("ACPI: NFIT: Install Notify() handler before
getting NFIT table"), acpi_nfit_probe() installs an ACPI notify handler
for the NFIT device before checking the presence of the NFIT table. If
that table is not there, 0 is returned without allocating the acpi_desc
object and setting the driver data pointer of the NFIT device. If the
platform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification
on the NFIT device at that point, acpi_nfit_uc_error_notify() will
dereference a NULL pointer.
Prevent that from occurring by adding an acpi_desc check against NULL
to acpi_nfit_uc_error_notify().7dCVE-2026-151705.5 MED5.3%
——2Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service23dCVE-2023-53146—5.3%
——2——CVE-2020-0078—5.3%
——2——CVE-2026-151655.5 MED5.3%
——2TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service22dCVE-2026-152354.3 MED5.3%
——2The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer.2dCVE-2023-5935—5.3%
——2——CVE-2026-142264.3 MED5.3%
——2The Easy Appointments WordPress plugin through 3.12.26 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules, and statuses.1dCVE-2025-57701—5.3%
——2——CVE-2023-31349—5.3%
——2——CVE-2026-21883—5.3%
——2——CVE-2026-3346—5.3%
——2——CVE-2025-363206.4 MED5.3%
——2IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.26dCVE-2022-20502—5.3%
——2——CVE-2026-125057.8 HIG5.3%
——2A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.3dCVE-2025-57703—5.3%
——2——CVE-2025-57702—5.3%
——2——CVE-2020-14264—5.3%
——2——CVE-2026-4479—5.3%
——2——CVE-2024-8090—5.3%
——2——CVE-2022-45452—5.3%
——2——CVE-2024-39579—5.3%
——2——CVE-2018-25302—5.3%
——2——CVE-2025-21016—5.3%
——2——CVE-2023-28603—5.3%
——2——CVE-2023-22593—5.3%
——2——CVE-2021-41216—5.3%
——2——CVE-2018-254355.3 MED5.3%
——2ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can deactivate customer accounts via the admin interface by tricking users into visiting attacker-controlled pages that submit requests to the regstatus endpoint with action=deny parameters.10dCVE-2024-37134—5.3%
——2——CVE-2025-37880—5.3%
——2——CVE-2022-22307—5.3%
——2——CVE-2025-14266—5.3%
——2——CVE-2020-36695—5.3%
——2——