Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-12109—26.0%
——8——CVE-2019-4349—26.0%
——8——CVE-2017-1190—25.9%
——8——CVE-2025-28169—25.9%
——8——CVE-2021-43940—25.9%
——8——CVE-2026-43899—25.9%
——8——CVE-2026-73156—25.9%
——8Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or MISP data, including STIX types, relationship_type, pattern prefixes, and MISP category/type values. Since ECharts interprets the formatter return value as HTML, crafted values can inject markup or script-capable content into the tooltip.
An attacker who can cause malicious conversion data to be processed can therefore inject content that executes when another user views the visualization and hovers over the affected slice. The patch replaces direct interpolation with dedicated formatter functions that call escapeHtml() on p.name, p.data.value, and p.value.20dCVE-2026-878217.1 HIG25.9%
——8Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions.6dCVE-2026-22247—25.9%
——8——CVE-2026-48945—25.9%
——8——CVE-2020-37175—25.9%
——8——CVE-2014-6133—25.9%
——8——CVE-2023-1937—25.9%
——8——CVE-2021-1757—25.9%
——8——CVE-2014-8537—25.9%
——8——CVE-2025-64134—25.9%
——8——CVE-2023-6693—25.9%
——8——CVE-2026-826044.3 MED25.9%
——8A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.15dCVE-2024-35679—25.9%
——8——CVE-2025-58207—25.9%
——8——CVE-2024-11708—25.9%
——8——CVE-2026-57633—25.9%
——8——CVE-2025-36137—25.9%
——8——CVE-2025-67575—25.9%
——8——CVE-2025-8526—25.9%
——8——CVE-2025-64327—25.9%
——8——CVE-2025-47910—25.9%
——8——CVE-2026-654905.3 MED25.9%
——8Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.54dCVE-2024-11200—25.9%
——8——CVE-2024-447976.1 MED25.9%
——8A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the view parameter.73dCVE-2013-5440—25.9%
——8——CVE-2021-30676—25.9%
——8——CVE-2026-1267—25.9%
——8——CVE-2024-0137—25.9%
——8——CVE-2015-4834—25.9%
——8——CVE-2022-20370—25.9%
——8——CVE-2025-30744—25.9%
——8——CVE-2024-36377—25.9%
——8——CVE-2024-36376—25.9%
——8——CVE-2023-1643—25.9%
——8——