Vulnerabilities exploitable today
352,317in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical2,257
- High7,708
- Medium7,032
- Low663
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-32483—2.9%
——1——CVE-2026-45175—2.9%
——1——CVE-2025-13362—2.9%
——1——CVE-2025-12373—2.9%
——1——CVE-2025-41421—2.9%
——1——CVE-2026-31730—2.9%
——1——CVE-2025-14162—2.9%
——1——CVE-2025-14161—2.9%
——1——CVE-2023-26299—2.9%
——1——CVE-2025-40810—2.9%
——1——CVE-2023-53623—2.9%
——1——CVE-2026-234457.8 HIG2.9%
——1In the Linux kernel, the following vulnerability has been resolved:
igc: fix page fault in XDP TX timestamps handling
If an XDP application that requested TX timestamping is shutting down
while the link of the interface in use is still up the following kernel
splat is reported:
[ 883.803618] [ T1554] BUG: unable to handle page fault for address: ffffcfb6200fd008
...
[ 883.803650] [ T1554] Call Trace:
[ 883.803652] [ T1554] <TASK>
[ 883.803654] [ T1554] igc_ptp_tx_tstamp_event+0xdf/0x160 [igc]
[ 883.803660] [ T1554] igc_tsync_interrupt+0x2d5/0x300 [igc]
...
During shutdown of the TX ring the xsk_meta pointers are left behind, so
that the IRQ handler is trying to touch them.
This issue is now being fixed by cleaning up the stale xsk meta data on
TX shutdown. TX timestamps on other queues remain unaffected.5hCVE-2020-8938—2.9%
——1——CVE-2020-8937—2.9%
——1——CVE-2021-25396—2.9%
——1——CVE-2026-234477.8 HIG2.9%
——1In the Linux kernel, the following vulnerability has been resolved:
net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
The same bounds-check bug fixed for NDP16 in the previous patch also
exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated
against the total skb length without accounting for ndpoffset, allowing
out-of-bounds reads when the NDP32 is placed near the end of the NTB.
Add ndpoffset to the nframes bounds check and use struct_size_t() to
express the NDP-plus-DPE-array size more clearly.
Compile-tested only.5hCVE-2026-27710—2.9%
——1——CVE-2025-14164—2.9%
——1——CVE-2025-8523—2.9%
——1——CVE-2026-31511—2.9%
——1——CVE-2025-40812—2.9%
——1——CVE-2021-47886—2.9%
——1——CVE-2025-40809—2.9%
——1——CVE-2026-31479—2.9%
——1——CVE-2026-97314.3 MED2.9%
——1The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce validation on the plugin_settings function. This makes it possible for unauthenticated attackers to update the plugin's notification text and CSS settings (wp_non_js_notification_text and wp_non_js_notification_css), injecting arbitrary content that is echoed unescaped on the frontend via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.16dCVE-2026-23276—2.9%
——1——CVE-2026-92364.3 MED2.9%
——1The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the cmac_campaigns_action function. This makes it possible for unauthenticated attackers to permanently delete arbitrary advertising campaigns, including their associated banner records and uploaded files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.2dCVE-2025-54042—2.9%
——1——CVE-2025-54030—2.9%
——1——CVE-2024-21476—2.9%
——1——CVE-2026-89094.3 MED2.9%
——1The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3. This is due to missing or incorrect nonce validation on the handleSaveGeneralSettings function. This makes it possible for unauthenticated attackers to modify the plugin's General Settings and inject arbitrary web scripts into the administrator's browser via the unescaped app_name attribute reflection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The injected script executes even when the supplied app_name value fails validation and is not persisted to the database, because the form is re-rendered with the attacker-supplied in-memory value on validation failure.2dCVE-2024-21947—2.9%
——1——CVE-2022-20368—2.9%
——1——CVE-2025-13657—2.9%
——1——CVE-2025-53327—2.9%
——1——CVE-2025-49449—2.9%
——1——CVE-2021-39709—2.9%
——1——CVE-2025-47681—2.9%
——1——CVE-2025-43835—2.9%
——1——CVE-2025-57885—2.9%
——1——