Vulnerabilities exploitable today
372,926in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,229
- High8,251
- Medium6,231
- Low615
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-46552—23.9%
——7——CVE-2024-9112—23.9%
——7——CVE-2026-41894—23.9%
——7——CVE-2022-47653—23.9%
——7——CVE-2009-1707—23.9%
——7——CVE-2025-66719—23.9%
——7——CVE-2024-52599—23.9%
——7——CVE-2026-1931—23.9%
——7——CVE-2025-10433—23.9%
——7——CVE-2022-27152—23.9%
——7——CVE-2025-22292—23.9%
——7——CVE-2023-45630—23.9%
——7——CVE-2026-3752—23.9%
——7——CVE-2026-789915.3 MED23.9%
——7Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)16dCVE-2026-254665.3 MED23.9%
——7Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.51dCVE-2022-30111—23.9%
——7——CVE-2024-33793—23.9%
——7——CVE-2026-20999—23.9%
——7——CVE-2025-24723—23.9%
——7——CVE-2025-32403—23.9%
——7——CVE-2019-25062—23.9%
——7——CVE-2026-654895.3 MED23.9%
——7Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.51dCVE-2024-10554—23.9%
——7——CVE-2024-3570—23.9%
——7——CVE-2026-41240—23.9%
——7——CVE-2020-15248—23.9%
——7——CVE-2026-697857.8 HIG23.9%
——7Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally.3dCVE-2026-49742—23.9%
——7Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such as log files. This issue affects TYPO3 CMS versions 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.51dCVE-2025-30087—23.9%
——7——CVE-2026-57323—23.9%
——7——CVE-2026-57665—23.9%
——7——CVE-2026-65765—23.9%
——7Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.46dCVE-2024-42649—23.9%
——7——CVE-2026-728108.6 HIG23.9%
——7SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication.17dCVE-2015-7440—23.9%
——7——CVE-2025-4525—23.9%
——7——CVE-2024-4176—23.9%
——7——CVE-2026-689007.6 HIG23.9%
——7Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText into content.innerHTML in the exported index.html. A board member could store an entity-encoded event-handler payload in a card title that remained inert on the live board but was reparsed and executed when a recipient clicked the card in the downloaded HTML export, allowing the script to read and transmit all board data contained in that export, including content added after the attacker's membership was removed. Version 10.23 builds the modal with DOM nodes and assigns untrusted values through textContent. This issue is fixed in version 10.23.2dCVE-2021-1436—23.9%
——7——CVE-2026-187539.1 CRI23.9%
——7The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.3d