Vulnerabilities exploitable today
352,785in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,880
- Medium7,174
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-460925.5 MED3.4%
——1In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw88: check for PCI upstream bridge existence
pci_upstream_bridge() returns NULL if the device is on a root bus. If
8821CE is installed in the system with such a PCI topology, the probing
routine will crash. This has probably been unnoticed as 8821CE is mostly
supplied in laptops where there is a PCI-to-PCI bridge located upstream
from the device. However the card might be installed on a system with
different configuration.
Check if the bridge does exist for the specific workaround to be applied.
Found by Linux Verification Center (linuxtesting.org) with Svace static
analysis tool.10dCVE-2026-46609—3.4%
——1——CVE-2025-14163—3.4%
——1——CVE-2025-54541—3.4%
——1——CVE-2023-53436—3.4%
——1——CVE-2023-53298—3.4%
——1——CVE-2025-39731—3.4%
——1——CVE-2023-53437—3.4%
——1——CVE-2025-43977—3.4%
——1——CVE-2022-32620—3.4%
——1——CVE-2026-25934—3.4%
——1——CVE-2026-56009—3.4%
——1——CVE-2025-39772—3.4%
——1——CVE-2025-4662—3.4%
——1——CVE-2026-46080—3.4%
——1——CVE-2026-281165.9 MED3.4%
——1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS.
This issue affects Progress Planner: from n/a through 1.9.0.4dCVE-2025-39706—3.4%
——1——CVE-2025-24183—3.4%
——1——CVE-2026-08115.4 MED3.4%
——1The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This makes it possible for unauthenticated attackers to delete form entry via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.1dCVE-2026-409737.0 HIG3.4%
——1A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); predictable temp directory / `ApplicationTemp` ownership verification. Versions that are no longer supported are also affected per vendor advisory.2dCVE-2023-53425—3.4%
——1——CVE-2025-69235—3.4%
——1——CVE-2025-25137—3.4%
——1——CVE-2025-43922—3.4%
——1——CVE-2025-3480—3.4%
——1——CVE-2026-126195.4 MED3.4%
——1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS).
This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.17dCVE-2023-53291—3.4%
——1——CVE-2026-45849—3.4%
——1——CVE-2026-53606—3.4%
——1——CVE-2026-283783.1 LOW3.4%
——1The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.16dCVE-2023-53611—3.4%
——1——CVE-2023-53568—3.4%
——1——CVE-2023-53435—3.4%
——1——CVE-2025-0012—3.4%
——1——CVE-2024-30406—3.4%
——1——CVE-2026-465465.4 MED3.4%
——1Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0.3dCVE-2026-4824—3.4%
——1——CVE-2025-36033—3.4%
——1——CVE-2026-1628—3.4%
——1——CVE-2026-585915.4 MED3.4%
——1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.12d