Vulnerabilities exploitable today
354,689in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,617
- High9,375
- Medium7,592
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-50419—5.3%
——2——CVE-2025-59732—5.3%
——2——CVE-2025-5324—5.3%
——2——CVE-2026-6252—5.3%
——2——CVE-2026-12490—5.3%
——2——CVE-2017-0843—5.3%
——2——CVE-2026-25417—5.3%
——2——CVE-2026-27286—5.3%
——2——CVE-2026-57617—5.3%
——2——CVE-2025-382127.8 HIG5.3%
——2In the Linux kernel, the following vulnerability has been resolved:
ipc: fix to protect IPCS lookups using RCU
syzbot reported that it discovered a use-after-free vulnerability, [0]
[0]: https://lore.kernel.org/all/67af13f8.050a0220.21dd3.0038.GAE@google.com/
idr_for_each() is protected by rwsem, but this is not enough. If it is
not protected by RCU read-critical region, when idr_for_each() calls
radix_tree_node_free() through call_rcu() to free the radix_tree_node
structure, the node will be freed immediately, and when reading the next
node in radix_tree_for_each_slot(), the already freed memory may be read.
Therefore, we need to add code to make sure that idr_for_each() is
protected within the RCU read-critical region when we call it in
shm_destroy_orphaned().2dCVE-2026-15301—5.3%
——2——CVE-2026-1032—5.3%
——2——CVE-2020-0057—5.3%
——2——CVE-2026-574026.5 MED5.3%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund and Return Order for WooCommerce flexible-refund-and-return-order-for-woocommerce allows Stored XSS.This issue affects Flexible Refund and Return Order for WooCommerce: from n/a through <= 1.0.51.19dCVE-2025-38086—5.3%
——2——CVE-2026-25355—5.3%
——2——CVE-2025-380827.8 HIG5.3%
——2In the Linux kernel, the following vulnerability has been resolved:
gpio: virtuser: fix potential out-of-bound write
If the caller wrote more characters, count is truncated to the max
available space in "simple_write_to_buffer". Check that the input
size does not exceed the buffer size. Write a zero termination
afterwards.2dCVE-2020-9118—5.3%
——2——CVE-2026-577836.5 MED5.3%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in merkulove Speaker speaker allows Stored XSS.This issue affects Speaker: from n/a through <= 4.1.13.19dCVE-2020-0338—5.3%
——2——CVE-2021-46834—5.3%
——2——CVE-2024-39820—5.3%
——2——CVE-2022-50384—5.3%
——2——CVE-2025-68075—5.3%
——2——CVE-2025-30036—5.3%
——2——CVE-2026-34556—5.3%
——2——CVE-2025-37186—5.3%
——2——CVE-2026-32491—5.3%
——2——CVE-2026-57638—5.3%
——2——CVE-2026-23181—5.3%
——2——CVE-2026-4268—5.3%
——2——CVE-2020-0056—5.3%
——2——CVE-2026-25331—5.3%
——2——CVE-2026-574146.5 MED5.3%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce – WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce – WoowBot: from n/a through <= 4.6.1.19dCVE-2026-34537—5.3%
——2——CVE-2022-20302—5.3%
——2——CVE-2026-34539—5.3%
——2——CVE-2026-130696.5 MED5.3%
——2An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulting resource exhaustion degrades availability for other operations.9dCVE-2025-38474—5.3%
——2——CVE-2026-395006.5 MED5.3%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor themesflat-addons-for-elementor allows Stored XSS.This issue affects themesflat-addons-for-elementor: from n/a through <= 2.3.2.7d