Vulnerabilities exploitable today
369,271in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,152
- High7,655
- Medium5,617
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-29454—20.2%
——6——CVE-2026-22522—20.2%
——6——CVE-2024-37663—20.2%
——6——CVE-2025-48905—20.2%
——6——CVE-2026-33321—20.2%
——6——CVE-2019-14591—20.2%
——6——CVE-2023-31871—20.2%
——6——CVE-2024-50560—20.2%
——6——CVE-2024-47190—20.2%
——6——CVE-2024-5551—20.2%
——6——CVE-2025-2197—20.2%
——6——CVE-2026-726666.8 MED20.2%
——6Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A user who is authorized to run Osquery live queries in one space can have a query carried out on hosts belonging to another space, resulting in disclosure of information from those hosts to the Osquery results data stream.4dCVE-2023-48773—20.2%
——6——CVE-2026-32484—20.1%
——6——CVE-2024-42671—20.1%
——6——CVE-2025-48056—20.1%
——6——CVE-2025-27304—20.1%
——6——CVE-2019-7006—20.1%
——6——CVE-2010-0225—20.1%
——6——CVE-2021-29050—20.1%
——6——CVE-2024-445734.7 MED20.1%
——6A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.63dCVE-2021-1079—20.1%
——6——CVE-2023-4975—20.1%
——6——CVE-2021-32039—20.1%
——6——CVE-2020-37210—20.1%
——6——CVE-2025-25085—20.1%
——6——CVE-2024-5409—20.1%
——6——CVE-2025-27303—20.1%
——6——CVE-2026-17089—20.1%
——6——CVE-2022-49657—20.1%
——6——CVE-2025-48093—20.1%
——6——CVE-2022-50846—20.1%
——6——CVE-2026-150096.1 MED20.1%
——6The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the attacker to control a domain whose origin string is a leading prefix of the target site's backend URL (e.g. https://example.co against https://example.com), and the victim must be an authenticated WordPress administrator who visits the attacker-controlled page while the File Manager admin screen is open.17dCVE-2020-7276—20.1%
——6——CVE-2024-1376—20.1%
——6——CVE-2025-39583—20.1%
——6——CVE-2026-196938.1 HIG20.1%
——6extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.10dCVE-2023-49224—20.1%
——6——CVE-2022-49727—20.1%
——6——CVE-2024-4661—20.1%
——6——