Vulnerabilities exploitable today
354,684in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,622
- High9,423
- Medium7,591
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-14313—5.1%
——2——CVE-2022-3884—5.1%
——2——CVE-2024-23380—5.1%
——2——CVE-2017-13163—5.1%
——2——CVE-2017-11030—5.1%
——2——CVE-2023-47857—5.1%
——2——CVE-2025-3154—5.1%
——2——CVE-2026-41430—5.1%
——2——CVE-2023-49135—5.1%
——2——CVE-2026-595236.5 MED5.1%
——2Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.18dCVE-2025-14552—5.1%
——2——CVE-2021-30337—5.1%
——2——CVE-2026-64526—5.1%
——2In the Linux kernel, the following vulnerability has been resolved:
ethtool: tsconfig: fix missing ethnl_ops_complete()
tsconfig_prepare_data() calls ethnl_ops_begin(), we need to call
ethnl_ops_complete() before returning the error.7dCVE-2021-22556—5.1%
——2——CVE-2017-0863—5.1%
——2——CVE-2025-401127.8 HIG5.1%
——2In the Linux kernel, the following vulnerability has been resolved:
sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara
The referenced commit introduced exception handlers on user-space memory
references in copy_from_user and copy_to_user. These handlers return from
the respective function and calculate the remaining bytes left to copy
using the current register contents. This commit fixes a couple of bad
calculations and a broken epilogue in the exception handlers. This will
prevent crashes and ensure correct return values of copy_from_user and
copy_to_user in the faulting case. The behaviour of memcpy stays unchanged.2dCVE-2021-30275—5.1%
——2——CVE-2026-75327.5 HIG5.1%
——2iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP address constraints.30dCVE-2021-30315—5.1%
——2——CVE-2026-664906.1 MED5.1%
——2Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.21dCVE-2026-476888.2 HIG5.1%
——2FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node endpoint. This allows remote wiping of host AES encryption credentials and deletion of all power management scheduled tasks, with no login, session, or CSRF token required. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue.8dCVE-2026-49241—5.1%
——2——CVE-2026-483535.5 MED5.1%
——2CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.15dCVE-2026-0972—5.1%
——2——CVE-2023-38291—5.1%
——2——CVE-2023-24573—5.1%
——2——CVE-2026-27508—5.1%
——2——CVE-2025-61871—5.1%
——2——CVE-2024-20859—5.1%
——2——CVE-2025-383337.8 HIG5.1%
——2In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to bail out in get_new_segment()
------------[ cut here ]------------
WARNING: CPU: 3 PID: 579 at fs/f2fs/segment.c:2832 new_curseg+0x5e8/0x6dc
pc : new_curseg+0x5e8/0x6dc
Call trace:
new_curseg+0x5e8/0x6dc
f2fs_allocate_data_block+0xa54/0xe28
do_write_page+0x6c/0x194
f2fs_do_write_node_page+0x38/0x78
__write_node_page+0x248/0x6d4
f2fs_sync_node_pages+0x524/0x72c
f2fs_write_checkpoint+0x4bc/0x9b0
__checkpoint_and_complete_reqs+0x80/0x244
issue_checkpoint_thread+0x8c/0xec
kthread+0x114/0x1bc
ret_from_fork+0x10/0x20
get_new_segment() detects inconsistent status in between free_segmap
and free_secmap, let's record such error into super block, and bail
out get_new_segment() instead of continue using the segment.2dCVE-2025-387357.8 HIG5.1%
——2In the Linux kernel, the following vulnerability has been resolved:
gve: prevent ethtool ops after shutdown
A crash can occur if an ethtool operation is invoked
after shutdown() is called.
shutdown() is invoked during system shutdown to stop DMA operations
without performing expensive deallocations. It is discouraged to
unregister the netdev in this path, so the device may still be visible
to userspace and kernel helpers.
In gve, shutdown() tears down most internal data structures. If an
ethtool operation is dispatched after shutdown(), it will dereference
freed or NULL pointers, leading to a kernel panic. While graceful
shutdown normally quiesces userspace before invoking the reboot
syscall, forced shutdowns (as observed on GCP VMs) can still trigger
this path.
Fix by calling netif_device_detach() in shutdown().
This marks the device as detached so the ethtool ioctl handler
will skip dispatching operations to the driver.2dCVE-2026-419725.4 MED5.1%
——2Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability.9dCVE-2024-58104—5.1%
——2——CVE-2026-112864.3 MED5.1%
——2Insufficient validation of untrusted input in Wallet in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)9dCVE-2024-34678—5.1%
——2——CVE-2026-108626.4 MED5.1%
——2The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2.3.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.9dCVE-2025-52563—5.1%
——2——CVE-2026-112944.3 MED5.1%
——2Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)9dCVE-2026-44712—5.1%
——2——CVE-2026-29828—5.1%
——2——