Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,357
- Medium5,357
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-1810—17.8%
——5——CVE-2024-26655—17.8%
——5——CVE-2025-39373—17.8%
——5——CVE-2017-6874—17.8%
——5——CVE-2024-52401—17.8%
——5——CVE-2025-55072—17.8%
——5——CVE-2025-66082—17.8%
——5——CVE-2025-60375—17.8%
——5——CVE-2025-50515—17.8%
——5——CVE-2026-264836.1 MED17.8%
——5Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input in the content parameter of the /templates endpoint, allowing an attacker to persistently inject malicious JavaScript code that is executed in the browsers of users who access the affected template.40dCVE-2026-54199—17.8%
——5Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the
request body in the application's link storing functionality
(//ServerClient_celink.htm), which is appended to the redirect target in
the 302 HTTP response. If a line feed is added, this will also be added
to the redirect link, resulting in the ability to control the response
headers. This issue affects TeamDavid through Rollout 524.6dCVE-2022-49482—17.8%
——5——CVE-2026-191657.5 HIG17.8%
——5Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)25dCVE-2025-39368—17.8%
——5——CVE-2025-54760—17.8%
——5——CVE-2026-47173—17.8%
——5——CVE-2026-45291—17.8%
——5——CVE-2023-51369—17.8%
——5——CVE-2025-1656—17.8%
——5——CVE-2026-679787.5 HIG17.8%
——5An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.23hCVE-2024-45463—17.8%
——5——CVE-2020-10742—17.8%
——5——CVE-2024-12771—17.8%
——5——CVE-2026-584254.3 MED17.8%
——5OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)6dCVE-2024-10860—17.8%
——5——CVE-2025-59269—17.8%
——5——CVE-2018-4178—17.8%
——5——CVE-2021-473528.4 HIG17.8%
——5In the Linux kernel, the following vulnerability has been resolved:
virtio-net: Add validation for used length
This adds validation for used length (might come
from an untrusted device) to avoid data corruption
or loss.28dCVE-2022-49108—17.8%
——5——CVE-2024-24704—17.8%
——5——CVE-2023-36476—17.8%
——5——CVE-2025-39388—17.8%
——5——CVE-2026-304597.1 HIG17.8%
——5An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message.58dCVE-2025-39353—17.8%
——5——CVE-2025-63708—17.8%
——5——CVE-2025-23254—17.8%
——5——CVE-2026-763692.7 LOW17.8%
——5In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads accept crafted filename input before writing log files. For more information see Manage roles and permissions in Splunk SOAR (Cloud) (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-cloud) and About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.11dCVE-2023-54358—17.8%
——5——CVE-2022-49551—17.8%
——5——CVE-2025-504847.1 HIG17.8%
——5Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.58d