Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-509436.1 MED26.1%
——8Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.52dCVE-2026-1134—26.1%
——8——CVE-2008-0718—26.1%
——8——CVE-2025-8020—26.1%
——8——CVE-2026-782629.8 CRI26.1%
——8Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.19dCVE-2026-40401—26.1%
——8——CVE-2025-10568—26.1%
——8——CVE-2014-7494—26.1%
——8——CVE-2014-7644—26.1%
——8——CVE-2005-0387—26.1%
——8——CVE-2025-57793—26.1%
——8——CVE-2023-27495—26.1%
——8——CVE-2024-3630—26.1%
——8——CVE-2021-20649—26.1%
——8——CVE-2019-4207—26.1%
——8——CVE-2025-5543—26.1%
——8——CVE-2024-30848—26.1%
——8——CVE-2026-83898.8 HIG26.1%
——8JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.63dCVE-2022-36277—26.1%
——8——CVE-2026-874466.5 MED26.1%
——8Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)5dCVE-2017-9985—26.1%
——8——CVE-2020-10702—26.1%
——8——CVE-2026-24960—26.1%
——8——CVE-2019-15878—26.1%
——8——CVE-2001-1066—26.1%
——8——CVE-2024-30556—26.1%
——8——CVE-2022-43114.7 MED26.1%
——8
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This
could allow a user with access to the log files to discover connection strings of data sources configured for the
DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users
unauthorized access to the underlying data sources.
68dCVE-2025-3631—26.1%
——8——CVE-2024-1888—26.1%
——8——CVE-2026-874366.5 MED26.1%
——8Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)5dCVE-2025-70981—26.1%
——8——CVE-2024-40774—26.1%
——8——CVE-2022-458847.0 HIG26.1%
——8An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.33dCVE-2025-6667—26.1%
——8——CVE-2024-30432—26.1%
——8——CVE-2024-13662—26.1%
——8——CVE-2020-35535—26.1%
——8——CVE-2026-34305—26.1%
——8——CVE-2023-4834—26.1%
——8——CVE-2026-857036.5 MED26.1%
——8A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation can lead to allocation of resources. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. This vulnerability only affects products that are no longer supported by the maintainer.4d