Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-8662—21.8%
——7——CVE-2005-4660—21.8%
——7——CVE-2009-5081—21.8%
——7——CVE-2024-40034—21.8%
——7——CVE-2024-42610—21.8%
——7——CVE-2024-47188—21.8%
——7——CVE-2021-30992—21.8%
——7——CVE-2026-76608—21.8%
——7Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.15dCVE-2024-42626—21.8%
——7——CVE-2024-5445—21.8%
——7——CVE-2024-43936—21.8%
——7——CVE-2024-40039—21.8%
——7——CVE-2025-30851—21.8%
——7——CVE-2026-22604—21.8%
——7——CVE-2024-40334—21.8%
——7——CVE-2024-40037—21.8%
——7——CVE-2026-517325.3 MED21.8%
——7Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.7dCVE-2026-140544.3 MED21.8%
——7Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)69dCVE-2024-7396—21.8%
——7——CVE-2026-27638—21.8%
——7——CVE-2024-42616—21.8%
——7——CVE-2024-42611—21.8%
——7——CVE-2025-14610—21.8%
——7——CVE-2025-15140—21.8%
——7——CVE-2025-67811—21.8%
——7——CVE-2024-41475—21.8%
——7——CVE-2025-10714.8 MED21.8%
——7A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.32dCVE-2016-11045—21.8%
——7——CVE-2025-5829—21.8%
——7——CVE-2024-42618—21.8%
——7——CVE-2026-75951—21.8%
——7Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.318dCVE-2024-42627—21.8%
——7——CVE-2020-24620—21.8%
——7——CVE-2023-47335—21.8%
——7——CVE-2024-35559—21.8%
——7——CVE-2025-36519—21.8%
——7——CVE-2025-5828—21.8%
——7——CVE-2024-46086—21.8%
——7——CVE-2026-517455.3 MED21.8%
——7Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker component.7dCVE-2020-5798—21.8%
——7——