Vulnerabilities exploitable today
369,638in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,121
- High7,610
- Medium5,709
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-7760—21.5%
——6——CVE-2026-27870—21.5%
——6An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS) payload into the 'Hostname' field of the configuration file resulting in a XSS in the path /upgrade/query.php?cmd=p+3%3Bversion. This issue affects Regesta Smart HD-PLC - TLDPH16D2:
11.02.05.10.02.69dCVE-2025-5651—21.5%
——6——CVE-2025-57917—21.5%
——6——CVE-2025-23464—21.5%
——6——CVE-2005-4773—21.5%
——6——CVE-2024-44121—21.5%
——6——CVE-2026-487965.3 MED21.5%
——6CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/SchemeHandler/FolderSchemeHandlerFactory.cs used filePath.StartsWith(rootFolder, StringComparison.OrdinalIgnoreCase) to decide whether a decoded and canonicalized request path remained inside rootFolder. That raw prefix test did not enforce a directory boundary, so a request such as ..%2fwww2/secret.txt could escape a configured www directory into a sibling www2 directory whose path shared the same string prefix. Applications that register FolderSchemeHandlerFactory for a custom scheme or an HTTP or HTTPS scheme can therefore serve local files outside the intended root when an attacker can cause the embedded browser to request the crafted URL. The issue affects both Unix-style paths such as /tmp/app/www2 and Windows paths such as C:\app\www2, and the fix appends a directory separator to the normalized root before comparison while rejecting null bytes and alternate data stream syntax. This issue is fixed in version 148.0.90.20dCVE-2004-0706—21.5%
——6——CVE-2026-94217.3 HIG21.5%
——6A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.47dCVE-2020-37147—21.5%
——6——CVE-2024-5600—21.5%
——6——CVE-2024-28568—21.5%
——6——CVE-2025-13575—21.5%
——6——CVE-2026-168595.3 MED21.5%
——6IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.22dCVE-2026-856997.5 HIG21.5%
——6jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata endpoints, allowing the server to fetch and return the target's response body to the attacker.4dCVE-2025-26531—21.5%
——6——CVE-2025-3074—21.5%
——6——CVE-2025-20049—21.5%
——6——CVE-2025-45755—21.5%
——6——CVE-2022-32926—21.5%
——6——CVE-2011-1717—21.5%
——6——CVE-2012-3345—21.5%
——6——CVE-2023-38486—21.5%
——6——CVE-2024-20403—21.5%
——6——CVE-2025-23180—21.5%
——6——CVE-2025-26981—21.5%
——6——CVE-2025-13977—21.5%
——6——CVE-2025-61837—21.5%
——6——CVE-2024-50456—21.5%
——6——CVE-2025-23433—21.5%
——6——CVE-2026-188918.2 HIG21.5%
——6IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.8dCVE-2005-2353—21.5%
——6——CVE-2023-47353—21.5%
——6——CVE-2019-19145—21.5%
——6——CVE-2025-23437—21.5%
——6——CVE-2026-32196—21.5%
——6——CVE-2022-22067—21.5%
——6——CVE-2026-26006.4 MED21.5%
——6The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.46dCVE-2026-48150—21.5%
——6——