Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,268
- High8,452
- Medium6,859
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-289346.5 MED35.3%
——11A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a malicious disk image may cause unexpected system termination.10dCVE-2005-0844—35.3%
——11——CVE-2026-933778.8 HIG35.3%
——11Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)4dCVE-2026-76565—35.3%
——11Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.736dCVE-2023-37275—35.3%
——11——CVE-2024-23865—35.3%
——11——CVE-2025-503419.8 CRI35.3%
——11A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false conditions, potentially leading to data exposure or further exploitation.83dCVE-2026-841238.8 HIG35.3%
——11Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.23dCVE-2023-30952—35.3%
——11——CVE-2024-23859—35.3%
——11——CVE-2024-23873—35.3%
——11——CVE-2017-17449—35.3%
——11——CVE-2024-45787—35.3%
——11——CVE-2023-3072—35.3%
——11——CVE-2015-7970—35.3%
——11——CVE-2024-23894—35.3%
——11——CVE-2023-5252—35.3%
——11——CVE-2024-23875—35.3%
——11——CVE-2026-47739—35.3%
——11——CVE-2022-35642—35.3%
——11——CVE-2026-6954—35.3%
——11Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or inject a dynamic iframe into the victim’s browser by sending a malicious URL via the 'urlDestino' parameter in '/portal.do'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, display phishing interfaces, or perform actions on the user’s behalf.87dCVE-2024-23882—35.3%
——11——CVE-2017-10219—35.3%
——11——CVE-2023-50808—35.3%
——11——CVE-2024-23863—35.3%
——11——CVE-2023-5705—35.3%
——11——CVE-2024-47087—35.3%
——11——CVE-2020-10123—35.3%
——11——CVE-2026-7502—35.3%
——11——CVE-2024-23893—35.3%
——11——CVE-2024-23891—35.3%
——11——CVE-2026-95661—35.3%
——11MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can cause an authenticated MISP user to visit a crafted URL containing a malicious type value can execute arbitrary JavaScript in the victim's browser within the MISP application origin.
Successful exploitation allows the attacker to read session cookies, perform actions on behalf of the victim, or exfiltrate sensitive data accessible from the MISP interface.
The vulnerability requires the victim to be authenticated and to actively navigate to the attacker-supplied URL.3dCVE-2026-78073—35.3%
——11Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors28dCVE-2026-53568—35.3%
——11——CVE-2023-45471—35.3%
——11——CVE-2022-404354.8 MED35.3%
——11Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module.79dCVE-2026-42870—35.3%
——11——CVE-2026-5790—35.3%
——11——CVE-2024-23858—35.3%
——11——CVE-2026-77027—35.3%
——11Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.32d