Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-20659—29.2%
——9——CVE-2026-3555—29.2%
——9——CVE-2020-37087—29.2%
——9——CVE-2023-46018—29.2%
——9——CVE-2025-55194—29.2%
——9——CVE-2005-1916—29.2%
——9——CVE-2021-27758—29.2%
——9——CVE-2017-15837—29.2%
——9——CVE-2006-7204—29.2%
——9——CVE-2012-0871—29.2%
——9——CVE-2021-32463—29.2%
——9——CVE-2025-13026—29.2%
——9——CVE-2025-3436—29.1%
——9——CVE-2022-2905—29.2%
——9——CVE-2025-36041—29.2%
——9——CVE-2023-46017—29.2%
——9——CVE-2024-3035—29.1%
——9——CVE-2023-38920—29.2%
——9——CVE-2019-0074—29.2%
——9——CVE-2019-18199—29.2%
——9——CVE-2025-9412—29.2%
——9——CVE-2026-428499.3 CRI29.2%
——9authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.57dCVE-2013-4343—29.2%
——9——CVE-2023-22863—29.2%
——9——CVE-2025-25732—29.2%
——9——CVE-2025-0318—29.2%
——9——CVE-2004-0712—29.2%
——9——CVE-2015-4176—29.2%
——9——CVE-2026-812138.6 HIG29.2%
——9IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.2dCVE-2026-816347.5 HIG29.2%
——9In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.1dCVE-2025-49549—29.1%
——9——CVE-2026-91256.4 MED29.1%
——9The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url shortcode attribute directly into the overlay configuration without scheme validation, allowing javascript: URIs to survive and be rendered as the href of a clickable anchor element by the presto-dynamic-overlay-ui web component. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.20dCVE-2024-50553—29.1%
——9——CVE-2020-9122—29.1%
——9——CVE-2014-5704—29.1%
——9——CVE-2009-0069—29.1%
——9——CVE-2024-11356—29.1%
——9——CVE-2007-2990—29.1%
——9——CVE-2007-5368—29.1%
——9——CVE-2024-13605—29.1%
——9——