Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-48915—25.6%
——8——CVE-2023-6690—25.6%
——8——CVE-2023-35907—25.6%
——8——CVE-2022-45792—25.6%
——8——CVE-2026-828559.8 CRI25.6%
——8@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers can use evidence from different zones, hostnames, origins, or repositories to bypass security guardrails for unrelated resources in the same stack.15dCVE-2020-8671—25.6%
——8——CVE-2026-23775—25.6%
——8——CVE-2024-41354—25.6%
——8——CVE-2026-6605—25.6%
——8——CVE-2021-25170—25.6%
——8——CVE-2024-21070—25.6%
——8——CVE-2024-10056—25.6%
——8——CVE-2026-54217—25.6%
——8Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An
attacker can send an email containing malicious JavaScript code. When a
user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.8dCVE-2018-0468—25.6%
——8——CVE-2021-3594—25.5%
——8——CVE-2026-7489—25.5%
——8——CVE-2024-12726—25.5%
——8——CVE-2023-46033—25.5%
——8——CVE-2025-64493—25.5%
——8——CVE-2024-50428—25.5%
——8——CVE-2022-30624—25.5%
——8——CVE-2026-23598—25.5%
——8——CVE-2025-57438—25.5%
——8——CVE-2026-590859.1 CRI25.5%
——8Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests.
This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.20dCVE-2023-43801—25.5%
——8——CVE-2019-8454—25.5%
——8——CVE-2024-25616—25.5%
——8——CVE-2025-1561—25.5%
——8——CVE-2022-29583—25.5%
——8——CVE-2026-12726—25.5%
——8——CVE-2026-40790—25.5%
——8——CVE-2025-47735—25.5%
——8——CVE-2026-2848—25.5%
——8——CVE-2025-202054.8 MED25.5%
——8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid administrative credentials.56dCVE-2011-0468—25.5%
——8——CVE-2026-50891—25.5%
——8——CVE-2026-20698—25.5%
——8——CVE-2022-40183—25.5%
——8——CVE-2023-43803—25.5%
——8——CVE-2026-4142—25.5%
——8——