Vulnerabilities exploitable today
369,139in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,634
Distribution · last window
- Critical2,182
- High7,846
- Medium5,729
- Low553
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-11878—19.6%
——6——CVE-2025-43739—19.6%
——6——CVE-2024-40959—19.6%
——6——CVE-2025-41111—19.6%
——6——CVE-2024-39910—19.6%
——6——CVE-2026-113716.1 MED19.6%
——6The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators.51dCVE-2024-38713—19.6%
——6——CVE-2017-9942—19.6%
——6——CVE-2024-53821—19.6%
——6——CVE-2022-21181—19.6%
——6——CVE-2025-45095—19.6%
——6——CVE-2026-25741—19.6%
——6——CVE-2023-28979—19.6%
——6——CVE-2025-28936—19.6%
——6——CVE-2026-3785—19.6%
——6——CVE-2025-30633—19.6%
——6——CVE-2026-21680—19.6%
——6——CVE-2026-105256.1 MED19.6%
——6The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators when they view the submitted entries.50dCVE-2026-32700—19.6%
——6——CVE-2023-1670—19.6%
——6——CVE-2026-178196.5 MED19.6%
——6Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)33dCVE-2025-52832—19.6%
——6——CVE-2026-792514.3 MED19.6%
——6Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)8dCVE-2024-43960—19.6%
——6——CVE-2026-77698.1 HIG19.6%
——6IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.33dCVE-2022-20489—19.6%
——6——CVE-2024-13387—19.6%
——6——CVE-2024-41162—19.6%
——6——CVE-2021-46767—19.6%
——6——CVE-2026-4502—19.6%
——6——CVE-2025-52833—19.6%
——6——CVE-2026-446536.5 MED19.6%
——6LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with only `VIEW` access to an MCP server can retrieve the server's decrypted admin-managed secrets through `GET /api/mcp/servers` and `GET /api/mcp/servers/:serverName`. The returned config includes plaintext values for `apiKey.key` and `oauth.client_secret`. This allows viewers of a shared MCP server to exfiltrate the underlying provider credentials. Version 0.8..4 contains a patch. Other remediations include: never returning decrypted admin-managed secrets to non-owners; redacting apiKey.key and oauth.client_secret from all API responses consider returning only boolean presence indicators for secrets, similar to the auth-values route pattern; and, if owners need to edit configs without re-entering secrets, preserving secrets server-side and returning placeholders instead of plaintext.46dCVE-2026-18377.5 HIG19.6%
——6A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data.
This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (selected by build flags).52dCVE-2023-5821—19.6%
——6——CVE-2025-1033—19.6%
——6——CVE-2025-32690—19.6%
——6——CVE-2024-34715—19.6%
——6——CVE-2025-57769—19.6%
——6——CVE-2023-28464—19.6%
——6——CVE-2025-62595—19.6%
——6——