Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,453
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-499786.1 MED26.4%
——8DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.56dCVE-2020-10598—26.4%
——8——CVE-2023-41053—26.4%
——8——CVE-2025-2645—26.4%
——8——CVE-2024-56939—26.4%
——8——CVE-2025-23966—26.4%
——8——CVE-2024-27995—26.4%
——8——CVE-2024-29103—26.4%
——8——CVE-2024-39680—26.4%
——8——CVE-2023-2850—26.4%
——8——CVE-2024-3073—26.4%
——8——CVE-2025-4063—26.4%
——8——CVE-2025-4062—26.4%
——8——CVE-2025-10003—26.4%
——8——CVE-2012-2284—26.4%
——8——CVE-2026-622388.8 HIG26.4%
——8OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data exfiltration.47dCVE-2026-737637.1 HIG26.4%
——8A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affected utility.5dCVE-2018-0368—26.4%
——8——CVE-2026-42731—26.4%
——8——CVE-2024-39681—26.4%
——8——CVE-2026-627977.8 HIG26.4%
——8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.30dCVE-2024-56938—26.4%
——8——CVE-2022-26323—26.4%
——8——CVE-2026-22906—26.4%
——8——CVE-2023-32094—26.4%
——8——CVE-2026-631434.3 MED26.4%
——8Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.43dCVE-2026-749075.9 MED26.4%
——8Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling directories by exploiting directory names that extend the base path string, such as requesting assets-secret when assets is the configured base.7dCVE-2026-795769.8 CRI26.4%
——8An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.6dCVE-2020-12299—26.4%
——8——CVE-2025-66020—26.4%
——8——CVE-2026-766144.3 MED26.4%
——8OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler without sanitization for path traversal sequences. The handler checks whether the supplied path exists on the filesystem, and the differing response messages leak whether the target path exists. An authenticated user with EOB Data Entry permissions can probe arbitrary filesystem paths on the server to determine file existence.6dCVE-2022-40261—26.4%
——8——CVE-2025-10310—26.4%
——8——CVE-2014-1949—26.4%
——8——CVE-2020-8733—26.4%
——8——CVE-2024-12616—26.4%
——8——CVE-2013-0580—26.4%
——8——CVE-2026-138258.8 HIG26.4%
——8Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)76dCVE-2023-22346—26.4%
——8——CVE-2025-7013—26.4%
——8——