Vulnerabilities exploitable today
352,791in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,306
- High8,002
- Medium7,177
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-39840—3.7%
——1——CVE-2023-53556—3.7%
——1——CVE-2025-33192—3.7%
——1——CVE-2023-53668—3.7%
——1——CVE-2026-120807.3 HIG3.7%
——1A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path.6dCVE-2024-34017—3.7%
——1——CVE-2023-20992—3.7%
——1——CVE-2022-25992—3.7%
——1——CVE-2023-20988—3.7%
——1——CVE-2026-46069—3.7%
——1——CVE-2026-82455.4 MED3.7%
——1Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL field into href="" (<a href="{$linkURL}" …>). Any authenticated admin or report viewer with access to `/dashboard/reports/forms/legacy` who clicks the crafted URL fires the payload in their session. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting4dCVE-2025-28894—3.7%
——1——CVE-2025-28892—3.7%
——1——CVE-2025-40581—3.7%
——1——CVE-2022-50508—3.7%
——1——CVE-2025-28891—3.7%
——1——CVE-2025-28933—3.7%
——1——CVE-2025-28883—3.7%
——1——CVE-2023-53333—3.7%
——1——CVE-2026-49988—3.7%
——1Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_output flow can register and read arbitrary local .json, .txt, .md, or .xml files without the file_system_read_file runSecretLint() safety check or Repomix packed-output validation, allowing MCP callers to bypass the local file-read secret-scanning boundary. This issue is fixed in version 1.14.1.9dCVE-2026-533698.4 HIG3.7%
——1In the Linux kernel, the following vulnerability has been resolved:
udf: reject descriptors with oversized CRC length
udf_read_tagged() skips CRC verification when descCRCLength +
sizeof(struct tag) exceeds the block size. A crafted UDF image can
set descCRCLength to an oversized value to bypass CRC validation
entirely; the descriptor is then accepted based solely on the 8-bit
tag checksum, which is trivially recomputable.
Reject such descriptors instead of silently accepting them. A
legitimate single-block descriptor should never have a CRC length that
exceeds the block.7dCVE-2026-120815.0 MED3.7%
——1The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are instantiated when an administrator views the stored entry. This is an incomplete fix of CVE-2025-7384 and CVE-2026-2599, whose deserialization paths were hardened while the entry-editor file-field path was missed.14dCVE-2020-36248—3.7%
——1——CVE-2025-62009—3.7%
——1——CVE-2026-23764—3.7%
——1——CVE-2024-21740—3.7%
——1——CVE-2024-54192—3.7%
——1——CVE-2025-38168—3.7%
——1——CVE-2025-28901—3.7%
——1——CVE-2022-49919—3.7%
——1——CVE-2020-8935—3.7%
——1——CVE-2020-0318—3.7%
——1——CVE-2023-53521—3.7%
——1——CVE-2026-32035—3.7%
——1——CVE-2025-38156—3.7%
——1——CVE-2025-53168—3.7%
——1——CVE-2023-20987—3.7%
——1——CVE-2017-11038—3.7%
——1——CVE-2023-53559—3.7%
——1——CVE-2025-59114—3.7%
——1——