Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-9686—25.6%
——8——CVE-2024-44009—25.6%
——8——CVE-2018-21086—25.6%
——8——CVE-2025-55834—25.6%
——8——CVE-2024-20928—25.6%
——8——CVE-2026-34496—25.6%
——8Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233.
This issue affects victor Web: before 7.1.47dCVE-2025-52042—25.6%
——8——CVE-2006-5664—25.6%
——8——CVE-2006-5663—25.6%
——8——CVE-2017-17161—25.6%
——8——CVE-2024-49661—25.6%
——8——CVE-2024-37803—25.6%
——8——CVE-2026-751636.5 MED25.6%
——8An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any authenticated user, including users with the low-privileged Standard role.7dCVE-2025-26335—25.6%
——8——CVE-2025-22302—25.6%
——8——CVE-2026-816787.5 HIG25.6%
——8AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSRF protections via the LiveLinks proxy endpoint to reach internal services and cloud metadata endpoints by encoding private IPv4 targets in transition address formats.17dCVE-2026-21914—25.6%
——8——CVE-2023-3289—25.6%
——8——CVE-2012-3735—25.6%
——8——CVE-2025-22720—25.6%
——8——CVE-2025-48914—25.6%
——8——CVE-2026-83609—25.6%
——8xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QName_exact validator with the multiline flag, so ^ and $ validate only one line instead of the complete name. createElementNS, createAttributeNS, createDocumentType, and createAttribute consequently accept a malformed XML name whose first line is valid and whose later text injects markup when serialized through either the default path or requireWellFormed: true. The triggering ECMAScript line terminators are U+000A, U+000D, U+2028, and U+2029. This issue is fixed in @xmldom/xmldom version 0.9.12.7dCVE-2026-140389.3 CRI25.6%
——8Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)76dCVE-2026-28781—25.6%
——8——CVE-2025-48915—25.6%
——8——CVE-2023-31089—25.6%
——8——CVE-2024-31406—25.6%
——8——CVE-2024-3984—25.6%
——8——CVE-2023-3937—25.6%
——8——CVE-2025-5726—25.6%
——8——CVE-2025-67857—25.6%
——8——CVE-2026-41911—25.6%
——8——CVE-2024-45286—25.6%
——8——CVE-2006-6906—25.6%
——8——CVE-2018-21085—25.6%
——8——CVE-2024-20762—25.6%
——8——CVE-2024-27728—25.6%
——8——CVE-2022-33280—25.6%
——8——CVE-2025-563205.4 MED25.6%
——8CobbleStone Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary code. NOTE: the Supplier reports that this is "Present only in an obsolete, unsupported version no longer in circulation."72dCVE-2021-26573—25.6%
——8——