Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,220
- High8,140
- Medium6,165
- Low607
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-65407—22.9%
——7——CVE-2026-143898.3 HIG22.9%
——7Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)70dCVE-2021-33478—22.9%
——7——CVE-2025-49194—22.9%
——7——CVE-2026-826035.4 MED22.9%
——7A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.9dCVE-2022-1792—22.9%
——7——CVE-2026-9375—22.9%
——7Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.28dCVE-2020-37195—22.9%
——7——CVE-2025-26987—22.9%
——7——CVE-2022-2950—22.9%
——7——CVE-2015-0603—22.9%
——7——CVE-2020-37177—22.9%
——7——CVE-2022-0642—22.9%
——7——CVE-2026-34262—22.9%
——7——CVE-2025-698485.4 MED22.9%
——7NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages without proper escaping. This allows user-controlled content to be rendered in the web interface when a delete operation fails due to protected relationships, potentially enabling execution of arbitrary client-side code in the context of a privileged user.23dCVE-2024-55199—22.9%
——7——CVE-2019-25341—22.9%
——7——CVE-2025-48915—22.9%
——7——CVE-2025-46747—22.9%
——7——CVE-2025-61152—22.9%
——7——CVE-2025-30639—22.9%
——7——CVE-2026-213118.0 HIG22.9%
——7Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.14dCVE-2026-760537.2 HIG22.9%
——7The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation is possible because WordPress's comment KSES allowlist permits the payload structure — an anchor tag with href and title attributes alongside a code tag — causing the malicious comment to be stored verbatim in the database, where it is later processed by the vulnerable parser during page translation.13dCVE-2025-9821—22.9%
——7——CVE-2026-151117.5 HIG22.9%
——7Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)63dCVE-2026-32948—22.9%
——7——CVE-2025-48914—22.9%
——7——CVE-2022-43978—22.9%
——7——CVE-2022-48469—22.9%
——7——CVE-2021-37124—22.9%
——7——CVE-2025-4087—22.9%
——7——CVE-2025-504206.5 MED22.9%
——7An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).67dCVE-2024-31404—22.9%
——7——CVE-2023-20564—22.9%
——7——CVE-2024-12566—22.8%
——7——CVE-2024-10186—22.8%
——7——CVE-2026-57338.8 HIG22.8%
——7Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.58dCVE-2024-58301—22.8%
——7——CVE-2023-49598—22.8%
——7——CVE-2026-27837—22.8%
——7——