Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,219
- High8,129
- Medium6,192
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-8734—24.5%
——7——CVE-2024-5880—24.5%
——7——CVE-2026-139066.5 MED24.5%
——7Out of bounds read in Codecs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)73dCVE-2025-4281—24.5%
——7——CVE-2026-46915—24.5%
——7——CVE-2026-143966.5 MED24.5%
——7Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)72dCVE-2023-28003—24.5%
——7——CVE-2023-50443—24.5%
——7——CVE-2019-10494—24.5%
——7——CVE-2026-34386—24.5%
——7——CVE-2020-11632—24.5%
——7——CVE-2026-861795.3 MED24.5%
——7A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used.4dCVE-2026-8074—24.5%
——7——CVE-2025-66296—24.5%
——7——CVE-2024-24920—24.5%
——7——CVE-2021-29266—24.5%
——7——CVE-2012-2148—24.5%
——7——CVE-2026-124217.2 HIG24.5%
——7The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.51dCVE-2024-12520—24.5%
——7——CVE-2026-408778.7 HIG24.5%
——7Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.3dCVE-2020-12359—24.5%
——7——CVE-2026-1639—24.5%
——7——CVE-2024-30216—24.5%
——7——CVE-2022-27835—24.5%
——7——CVE-2022-44560—24.5%
——7——CVE-2015-1776—24.5%
——7——CVE-2026-138476.5 MED24.5%
——7Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)72dCVE-2025-62723—24.5%
——7——CVE-2026-603308.5 HIG24.4%
——7Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).43dCVE-2026-140596.5 MED24.5%
——7Insufficient policy enforcement in Related-Website-Sets in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)73dCVE-2026-3319—24.5%
——7——CVE-2024-13361—24.5%
——7——CVE-2026-143866.5 MED24.5%
——7Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)72dCVE-2020-24721—24.5%
——7——CVE-2019-1803—24.5%
——7——CVE-2023-30431—24.5%
——7——CVE-2026-81417.2 HIG24.5%
——7The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.75dCVE-2026-78073—24.5%
——7Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors15dCVE-2026-141466.5 MED24.5%
——7Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)73dCVE-2007-1865—24.4%
——7——