Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,210
- High7,846
- Medium6,388
- Low707
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2009-0579—28.1%
——8——CVE-2020-27557—28.1%
——8——CVE-2015-1878—28.1%
——8——CVE-2015-5830—28.1%
——8——CVE-2025-60556—28.1%
——8——CVE-2010-5204—28.1%
——8——CVE-2017-3740—28.1%
——8——CVE-2015-0489—28.1%
——8——CVE-2004-0701—28.1%
——8——CVE-2010-2386—28.1%
——8——CVE-2026-140336.5 MED28.1%
——8Insufficient policy enforcement in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)77dCVE-2023-5310—28.1%
——8——CVE-2025-41430—28.1%
——8——CVE-2024-3951—28.1%
——8——CVE-2026-713437.8 HIG28.1%
——8Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.1dCVE-2026-83608—28.1%
——8xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed: true but emits DocumentType.name verbatim. A name containing > or whitespace can terminate the <!DOCTYPE ...> declaration and inject sibling markup; the value can be supplied through createDocumentType() on the 0.8.x and unscoped lines or through a direct DocumentType.name property write on every affected line. The default path and legacy creation-time behavior remain permissive, while the vulnerable strict path fails to enforce an XML Name. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.8dCVE-2026-72018.8 HIG28.1%
——8CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to modify account properties of other users, potentially leading to account compromise. Successful exploitation requires knowledge of values that are not generally exposed to low-privileged users.56dCVE-2025-60555—28.1%
——8——CVE-2024-8693—28.1%
——8——CVE-2021-28707—28.1%
——8——CVE-2024-20829—28.1%
——8——CVE-2026-97984.3 MED28.1%
——8A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection. This allows continued authentication attempts and token issuance even when the account should be locked, potentially enabling further unauthorized access attempts.28dCVE-2024-34462—28.1%
——8——CVE-2019-25422—28.1%
——8——CVE-2026-3962—28.1%
——8——CVE-2026-614298.5 HIG28.1%
——8PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redirects and read internal responses including sensitive canary values.65dCVE-2025-4124—28.1%
——8——CVE-2018-253718.2 HIG28.1%
——8mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information.55dCVE-2024-22250—28.1%
——8——CVE-2025-61938—28.1%
——8——CVE-2017-7082—28.1%
——8——CVE-2025-55036—28.1%
——8——CVE-2026-42594—28.1%
——8——CVE-2025-5681—28.1%
——8——CVE-2026-614308.5 HIG28.1%
——8PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.63dCVE-2016-4595—28.1%
——8——CVE-2015-5873—28.1%
——8——CVE-2015-5871—28.1%
——8——CVE-2017-7058—28.1%
——8——CVE-2026-56302—28.1%
——8——