Vulnerabilities exploitable today
352,832in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,306
- High8,005
- Medium7,178
- Low677
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-12539—3.7%
——1Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts. A workload inside a sandbox, which the threat model treats as untrusted, can therefore defeat the documented ICMP egress block to perform network reconnaissance and exfiltrate data over an ICMP covert channel, regardless of the configured allowlist.27dCVE-2026-24007—3.7%
——1——CVE-2023-28545—3.7%
——1——CVE-2026-115815.9 MED3.7%
——1The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's session. A missing capability check in the Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13's post-duplication action additionally lets the Contributor publish the malicious form so an administrator renders it.27dCVE-2026-577518.1 HIG3.7%
——1Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.25dCVE-2026-31996—3.7%
——1——CVE-2026-29050—3.7%
——1——CVE-2025-68527—3.7%
——1——CVE-2026-5923—3.7%
——1Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.18dCVE-2025-0432—3.7%
——1——CVE-2025-68528—3.7%
——1——CVE-2025-14159—3.7%
——1——CVE-2026-21338—3.7%
——1——CVE-2025-15363—3.7%
——1——CVE-2026-26317—3.7%
——1——CVE-2024-34610—3.7%
——1——CVE-2016-11027—3.7%
——1——CVE-2026-24632—3.7%
——1——CVE-2018-254236.2 MED3.7%
——1Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a malicious buffer of 700 bytes into the IP address or domain input field to trigger a denial of service condition.5dCVE-2018-21077—3.7%
——1——CVE-2025-220604.7 MED3.7%
——1In the Linux kernel, the following vulnerability has been resolved:
net: mvpp2: Prevent parser TCAM memory corruption
Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM
information, from concurrent modifications.
Both the TCAM and SRAM tables are indirectly accessed by configuring
an index register that selects the row to read or write to. This means
that operations must be atomic in order to, e.g., avoid spreading
writes across multiple rows. Since the shadow SRAM array is used to
find free rows in the hardware table, it must also be protected in
order to avoid TOCTOU errors where multiple cores allocate the same
row.
This issue was detected in a situation where `mvpp2_set_rx_mode()` ran
concurrently on two CPUs. In this particular case the
MVPP2_PE_MAC_UC_PROMISCUOUS entry was corrupted, causing the
classifier unit to drop all incoming unicast - indicated by the
`rx_classifier_drops` counter.13dCVE-2019-2190—3.7%
——1——CVE-2025-39894—3.7%
——1——CVE-2024-28046—3.7%
——1——CVE-2025-59135—3.7%
——1——CVE-2023-22383—3.7%
——1——CVE-2019-9472—3.7%
——1——CVE-2018-21073—3.7%
——1——CVE-2020-11173—3.7%
——1——CVE-2023-28570—3.7%
——1——CVE-2019-9435—3.7%
——1——CVE-2024-45355—3.7%
——1——CVE-2024-24977—3.7%
——1——CVE-2025-5344—3.7%
——1——CVE-2025-38093—3.7%
——1——CVE-2021-35085—3.7%
——1——CVE-2024-29015—3.7%
——1——CVE-2025-64469—3.7%
——1——CVE-2023-53600—3.7%
——1——CVE-2025-38092—3.7%
——1——