Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,224
- High7,930
- Medium6,432
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-39532—27.7%
——8——CVE-2026-487616.1 MED27.7%
——8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on <object>, <applet>, <iframe>, and <img>, and <meta http-equiv="refresh"> URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.57dCVE-2009-2840—27.7%
——8——CVE-2023-24399—27.7%
——8——CVE-2015-5899—27.7%
——8——CVE-2025-13686—27.7%
——8——CVE-2024-23588—27.7%
——8——CVE-2016-4701—27.7%
——8——CVE-2025-52095—27.7%
——8——CVE-2024-5767—27.7%
——8——CVE-2025-13688—27.7%
——8——CVE-2024-52941—27.7%
——8——CVE-2026-25096.4 MED27.7%
——8The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and including, 2.0.8. This is due to an incomplete event handler blocklist in the 'pagelayer_xss_content' XSS filtering function, which blocks common, but not all, event handlers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.53dCVE-2023-34154—27.7%
——8——CVE-2011-0988—27.7%
——8——CVE-2021-39143—27.7%
——8——CVE-2026-24978—27.7%
——8——CVE-2009-2834—27.7%
——8——CVE-2026-161034.3 MED27.7%
——8A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by the user.16dCVE-2022-4233—27.7%
——8——CVE-2026-32878—27.7%
——8——CVE-2025-68531—27.7%
——8——CVE-2024-7049—27.7%
——8Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.5dCVE-2023-41626—27.7%
——8——CVE-2008-4475—27.7%
——8——CVE-2022-41845—27.7%
——8——CVE-2024-37003—27.7%
——8——CVE-2024-52594—27.7%
——8——CVE-2026-7627—27.7%
——8——CVE-2015-5896—27.7%
——8——CVE-2017-2352—27.7%
——8——CVE-2026-25360—27.7%
——8——CVE-2024-11902—27.7%
——8——CVE-2023-39994—27.7%
——8——CVE-2015-5868—27.7%
——8——CVE-2002-0213—27.7%
——8——CVE-2024-2380—27.7%
——8——CVE-2018-1000635—27.7%
——8——CVE-2019-11098—27.7%
——8——CVE-2025-452427.7 HIG27.7%
——8Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.74d