Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,357
- Medium5,357
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-25992—17.7%
——5——CVE-2025-3919—17.7%
——5——CVE-2023-0495—17.7%
——5——CVE-2026-2077—17.7%
——5——CVE-2025-57109—17.7%
——5——CVE-2024-40069—17.7%
——5——CVE-2024-49277—17.7%
——5——CVE-2023-42893—17.7%
——5——CVE-2024-44113—17.7%
——5——CVE-2025-43302—17.7%
——5——CVE-2025-13015—17.7%
——5——CVE-2026-73157—17.7%
——5Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, event information, organization names, tags, tag colors, TLP labels, distribution labels, and error/flash text may be controlled by the remote MISP server, a malicious or compromised remote instance could return crafted values that inject HTML or script-capable content into the cti-transmute interface.
The patch explicitly notes that remote-derived values must not reach innerHTML, and replaces string-built rows and badges with DOM nodes populated through textContent. It also restricts remote-controlled tag colors to six-digit hexadecimal values, preventing malicious CSS values such as url(...).6dCVE-2024-41737—17.7%
——5——CVE-2024-41729—17.7%
——5——CVE-2026-1650—17.7%
——5——CVE-2024-13887—17.7%
——5——CVE-2026-490964.3 MED17.7%
——5Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being displayed. An authenticated user holding privileges to comment on a case could store such a comment, after which that case became inaccessible to every user who opened it until the stored comment was removed.4dCVE-2022-29959—17.7%
——5——CVE-2026-102374.7 MED17.7%
——5A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user of the component User Management Module. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.41dCVE-2023-28749—17.7%
——5——CVE-2022-30320—17.7%
——5——CVE-2024-39596—17.7%
——5——CVE-2025-3019—17.7%
——5——CVE-2025-57997—17.7%
——5——CVE-2026-187897.5 HIG17.7%
——5The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as to persistently change some of its settings.6dCVE-2026-1870—17.7%
——5——CVE-2026-66919—17.7%
——5Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions originating from graph data were interpolated directly into HTML used to construct the modal headers.
An attacker able to supply or modify graph data could insert a malicious HTML or JavaScript payload into a node’s label or description. The payload would be parsed and executed in the application’s origin when a user opened the affected node’s inspect or edit modal.
Successful exploitation could allow the attacker to access information available to the victim, modify application data, or perform actions using the victim’s active session.
The vulnerability has been addressed by creating the modal elements without embedding graph data in HTML and assigning node labels and descriptions through textContent.33dCVE-2026-446927.7 HIG17.7%
——5Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that authorizes access only to the supplied Sharp entity instance, but then reads the target storage disk and path from request parameters. Because the requested storage object is not bound to the authorized entity instance, an authenticated Sharp user who can view one valid record may use that record as an authorization anchor to download unrelated disk-relative objects from configured Laravel Storage disks. The confirmed impact is authenticated disclosure of unrelated objects from configured Laravel Storage disks. This issue does not imply arbitrary host filesystem access outside configured Laravel Storage disk roots. This issue has been patched in version 9.22.0.40dCVE-2026-4324—17.7%
——5——CVE-2025-37852—17.7%
——5——CVE-2026-2078—17.7%
——5——CVE-2025-14339—17.7%
——5——CVE-2026-25907—17.7%
——5——CVE-2024-41866—17.7%
——5——CVE-2025-13157—17.7%
——5——CVE-2020-27270—17.7%
——5——CVE-2024-50148—17.7%
——5——CVE-2026-547377.3 HIG17.7%
——5@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to Object.prototype. This issue is fixed in version 2.0.5.32dCVE-2023-0496—17.7%
——5——CVE-2022-39349—17.7%
——5——