Vulnerabilities exploitable today
369,638in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,121
- High7,610
- Medium5,709
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-119045.3 MED21.5%
——6IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.27dCVE-2025-10463—21.5%
——6——CVE-2025-9488—21.5%
——6——CVE-2026-114585.3 MED21.5%
——6A weakness has been identified in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This issue affects some unknown processing of the file /base-boot/actuator of the component Boot Actuator Endpoint. Executing a manipulation can lead to information disclosure. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.47dCVE-2024-37521—21.5%
——6——CVE-2026-40937—21.5%
——6——CVE-2022-38653—21.5%
——6——CVE-2026-168595.3 MED21.5%
——6IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.22dCVE-2024-46410—21.5%
——6——CVE-2024-28568—21.5%
——6——CVE-2024-5600—21.5%
——6——CVE-2025-13575—21.5%
——6——CVE-2026-26744—21.5%
——6——CVE-2023-23640—21.5%
——6——CVE-2025-69270—21.5%
——6——CVE-2023-6676—21.5%
——6——CVE-2025-41254—21.5%
——6——CVE-2026-33541—21.5%
——6——CVE-2023-23639—21.5%
——6——CVE-2026-34903—21.5%
——6——CVE-2025-43881—21.5%
——6——CVE-2026-32198—21.5%
——6——CVE-2024-27896—21.5%
——6——CVE-2026-39935—21.5%
——6Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS). This issue was remediated only on the `master` branch.49dCVE-2024-12448—21.5%
——6——CVE-2025-23181—21.5%
——6——CVE-2026-23541—21.5%
——6——CVE-2025-23451—21.5%
——6——CVE-2026-6819—21.5%
——6——CVE-2026-22711—21.5%
——6Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.49dCVE-2024-28567—21.5%
——6——CVE-2026-32236—21.5%
——6——CVE-2017-18778—21.5%
——6——CVE-2026-06646.4 MED21.5%
——6The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.46dCVE-2024-0319—21.5%
——6——CVE-2026-601902.2 LOW21.5%
——6Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).43dCVE-2026-26006.4 MED21.5%
——6The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.46dCVE-2025-23437—21.5%
——6——CVE-2023-47353—21.5%
——6——CVE-2026-32196—21.5%
——6——