Vulnerabilities exploitable today
369,392in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,099
- High7,540
- Medium5,594
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2003-1476—20.9%
——6——CVE-2023-32377—20.9%
——6——CVE-2026-50885—20.9%
——6——CVE-2023-21733—20.9%
——6——CVE-2025-9167—20.9%
——6——CVE-1999-0476—20.9%
——6——CVE-2026-30910—20.9%
——6——CVE-2026-500919.1 CRI20.9%
——6Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical).60dCVE-2026-710387.5 HIG20.9%
——6Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).18dCVE-2021-21526—20.9%
——6——CVE-2026-20985—20.9%
——6——CVE-2026-3216—20.9%
——6——CVE-2024-7244—20.9%
——6——CVE-2026-25309—20.9%
——6——CVE-2026-177285.4 MED20.9%
——6Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)28dCVE-2023-40104—20.9%
——6——CVE-2025-9105—20.9%
——6——CVE-2021-21448—20.9%
——6——CVE-2025-39498—20.9%
——6——CVE-2019-25521—20.9%
——6——CVE-2026-580344.8 MED20.8%
——6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser.
This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue.
This issue affects CheckUser: from 1.46.0-rc.0 before 1.46.0.60dCVE-2024-41044—20.9%
——6——CVE-2021-1101—20.9%
——6——CVE-2025-9104—20.9%
——6——CVE-2026-40767—20.9%
——6——CVE-2020-37256—20.9%
——6——CVE-2024-5343—20.9%
——6——CVE-2016-6043—20.9%
——6——CVE-2026-580354.8 MED20.8%
——6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue.60dCVE-2022-45448—20.9%
——6——CVE-2025-27726—20.9%
——6——CVE-2024-27168—20.8%
——6——CVE-2025-13478—20.8%
——6——CVE-2017-3741—20.8%
——6——CVE-2026-35658—20.8%
——6——CVE-2020-3595—20.8%
——6——CVE-2024-49687—20.8%
——6——CVE-2021-29948—20.8%
——6——CVE-2026-4745—20.8%
——6——CVE-2025-9954—20.8%
——6——