Vulnerabilities exploitable today
352,788in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,882
- Medium7,175
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-43153—3.6%
——1——CVE-2026-7038—3.6%
——1——CVE-2026-287355.4 MED3.6%
——1Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL.. Mattermost Advisory ID: MMSA-2026-006283dCVE-2026-43222—3.6%
——1——CVE-2017-11091—3.6%
——1——CVE-2026-95225.4 MED3.6%
——1Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.4dCVE-2026-126895.4 MED3.6%
——1The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.2dCVE-2019-256585.5 MED3.6%
——1a-Mac Address Change 5.4 contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input to registration form fields. Attackers can paste 212 bytes of data into the 'Your Name', 'Your Company', or 'Register Code' fields and click the Register button to trigger a denial of service crash.2dCVE-2025-63060—3.6%
——1——CVE-2023-53579—3.6%
——1——CVE-2025-38228—3.6%
——1——CVE-2025-62439—3.6%
——1——CVE-2026-43258—3.6%
——1——CVE-2024-13710—3.6%
——1——CVE-2023-30698—3.6%
——1——CVE-2023-53396—3.6%
——1——CVE-2024-13682—3.6%
——1——CVE-2025-23985—3.6%
——1——CVE-2024-57974—3.6%
——1——CVE-2025-38621—3.6%
——1——CVE-2017-13172—3.6%
——1——CVE-2026-29839—3.6%
——1——CVE-2026-27846—3.6%
——1——CVE-2017-14898—3.6%
——1——CVE-2024-39293—3.6%
——1——CVE-2025-24533—3.6%
——1——CVE-2026-236955.4 MED3.6%
——1Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html directive without sanitization. An attacker with content/:models/manage permission can inject arbitrary JavaScript into the Display template, which executes in the browser of any user viewing the collection items list.12dCVE-2026-141845.4 MED3.6%
——1The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.5dCVE-2026-30363—3.6%
——1——CVE-2017-11019—3.6%
——1——CVE-2026-46162—3.6%
——1——CVE-2017-13165—3.6%
——1——CVE-2017-11018—3.6%
——1——CVE-2017-11032—3.6%
——1——CVE-2025-0990—3.6%
——1——CVE-2026-130226.5 MED3.6%
——1Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)26dCVE-2024-20854—3.6%
——1——CVE-2017-11073—3.6%
——1——CVE-2017-14901—3.6%
——1——CVE-2017-11016—3.6%
——1——