Vulnerabilities exploitable today
367,165in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,274
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-27905—17.1%
——5——CVE-2026-48152—17.1%
——5——CVE-2024-3134—17.1%
——5——CVE-2025-31426—17.1%
——5——CVE-2025-46259—17.1%
——5——CVE-2025-1560—17.1%
——5——CVE-2025-31917—17.1%
——5——CVE-2023-52989—17.1%
——5——CVE-2026-31834—17.1%
——5——CVE-2024-5141—17.1%
——5——CVE-2026-277376.5 MED17.1%
——5BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicious actor to craft and carry out a targeted XSS attack, activated on anyone replaying the recording. This issue has been fixed 3.0.19.38dCVE-2021-36915—17.1%
——5——CVE-2026-42886—17.1%
——5——CVE-2025-62421—17.1%
——5——CVE-2025-31057—17.1%
——5——CVE-2025-31638—17.1%
——5——CVE-2020-13593—17.1%
——5——CVE-2024-5342—17.1%
——5——CVE-2025-0627—17.1%
——5——CVE-2006-6730—17.1%
——5——CVE-2025-13480—17.1%
——5——CVE-2018-11856—17.1%
——5——CVE-2026-2840—17.1%
——5——CVE-2026-134157.2 HIG17.1%
——5The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.3dCVE-2024-48442—17.1%
——5——CVE-2025-47477—17.1%
——5——CVE-2026-792134.3 MED17.1%
——5Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)3dCVE-2024-3997—17.1%
——5——CVE-2024-40113—17.1%
——5——CVE-2023-22689—17.1%
——5——CVE-2025-31925—17.1%
——5——CVE-2025-22215—17.1%
——5——CVE-2025-52896—17.1%
——5——CVE-2024-49241—17.1%
——5——CVE-2026-57146.4 MED17.1%
——5The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.39dCVE-2026-775419.1 CRI17.1%
——5A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.3dCVE-2024-3066—17.1%
——5——CVE-2026-29367.2 HIG17.1%
——5The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an admin user accesses the Traffic by Title section.38dCVE-2025-52947—17.1%
——5——CVE-2023-2431—17.1%
——5——