Vulnerabilities exploitable today
367,165in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,274
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-46821—17.2%
——5——CVE-2026-425568.9 HIG17.2%
——5Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and send the public preview link /p/<postId>?share=true to another user. The preview page renders that stored HTML with dangerouslySetInnerHTML on the main application origin. This issue has been patched in version 2.21.7.38dCVE-2025-10575—17.2%
——5——CVE-2026-2040—17.2%
——5——CVE-2025-49037—17.2%
——5——CVE-2025-46461—17.2%
——5——CVE-2025-46453—17.2%
——5——CVE-2022-26357—17.2%
——5——CVE-2020-7320—17.2%
——5——CVE-2026-817245.3 MED17.2%
——5NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python's recursion limit and raise an unhandled RecursionError, crashing applications that parse user-supplied feature structures or feature grammars.3dCVE-2026-4189—17.2%
——5——CVE-2025-10144—17.2%
——5——CVE-2023-0350—17.2%
——5——CVE-2025-11365—17.2%
——5——CVE-2025-26919—17.2%
——5——CVE-2025-12836—17.2%
——5——CVE-2022-4095—17.2%
——5——CVE-2025-54210—17.2%
——5——CVE-2025-20946—17.2%
——5——CVE-2025-621843.4 LOW17.2%
——5Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.38dCVE-2025-22673—17.2%
——5——CVE-2025-38575—17.2%
——5——CVE-2021-29861—17.2%
——5——CVE-2025-50926—17.2%
——5——CVE-2025-46300—17.2%
——5——CVE-2026-2451—17.2%
——5——CVE-2026-44729—17.2%
——5——CVE-2023-6039—17.2%
——5——CVE-2025-62800—17.2%
——5——CVE-2026-54040—17.2%
——5——CVE-2026-77989—17.2%
——5Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.3dCVE-2025-48811—17.2%
——5——CVE-2026-94464.7 MED17.2%
——5A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.39dCVE-2025-66470—17.2%
——5——CVE-2024-26715—17.2%
——5——CVE-2026-9806—17.2%
——5——CVE-2024-48233—17.2%
——5——CVE-2026-343722.7 LOW17.2%
——5Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even have permission for contacts. This issue has been patched in versions 2.6.22 and 3.0.5.38dCVE-2025-9225—17.2%
——5——CVE-2025-7636—17.2%
——5——