Vulnerabilities exploitable today
353,240in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,348
- High8,119
- Medium7,274
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-396179.6 CRI4.0%
——1Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.3dCVE-2026-41384—4.0%
——1——CVE-2025-39790—4.0%
——1——CVE-2025-70560—4.0%
——1——CVE-2020-0151—4.0%
——1——CVE-2020-0044—4.0%
——1——CVE-2020-0437—4.0%
——1——CVE-2025-61973—4.0%
——1——CVE-2025-20932—4.0%
——1——CVE-2020-0145—4.0%
——1——CVE-2025-20930—4.0%
——1——CVE-2021-30263—4.0%
——1——CVE-2025-20933—4.0%
——1——CVE-2025-22240—4.0%
——1——CVE-2022-45874—4.0%
——1——CVE-2020-27039—4.0%
——1——CVE-2025-13958—4.0%
——1——CVE-2025-20928—4.0%
——1——CVE-2023-53481—4.0%
——1——CVE-2024-3479—4.0%
——1——CVE-2025-38598—4.0%
——1——CVE-2026-27609—4.0%
——1——CVE-2024-24901—4.0%
——1——CVE-2025-21094—4.0%
——1——CVE-2024-56559—4.0%
——1——CVE-2024-28953—4.0%
——1——CVE-2025-24520—4.0%
——1——CVE-2025-39883—4.0%
——1——CVE-2026-396218.8 HIG4.0%
——1Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2.3.2.5.3dCVE-2026-396209.6 CRI4.0%
——1Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.3dCVE-2026-24201—4.0%
——1——CVE-2026-488157.5 HIG4.0%
——1sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1.12dCVE-2026-526843.7 LOW4.0%
——1If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the
child records are used immediately if not expired and thus valid, or the
records are expired, and in that case not used. So this case
can only happen if almost expired records are used to refresh the
authoritative NS records.4dCVE-2026-341934.3 MED4.0%
——1Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.
A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.6dCVE-2025-22053—4.0%
——1——CVE-2025-38536—4.0%
——1——CVE-2025-38667—4.0%
——1——CVE-2024-6619—4.0%
——1——CVE-2026-39855—4.0%
——1——CVE-2025-32797—4.0%
——1——