Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,296
- High9,357
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-0483—16.5%
——5——CVE-2026-29071—16.5%
——5——CVE-2026-132316.1 MED16.5%
——5Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.23dCVE-2026-110619.6 CRI16.5%
——5Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)38dCVE-2026-2819—16.5%
——5——CVE-2026-31802—16.5%
——5——CVE-2025-61652—16.5%
——5——CVE-2021-1787—16.5%
——5——CVE-2024-20794—16.5%
——5——CVE-2026-43577—16.5%
——5——CVE-2026-84036.1 MED16.5%
——5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Stored XSS.
This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.4.0.
NOTE: The vendor was contacted and it was learned that the product is not supported.60dCVE-2026-73806.1 MED16.5%
——5Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows XSS Targeting HTML Attributes.
This issue affects Access Control System (GKS): before Version 2.54dCVE-2026-90666.1 MED16.5%
——5The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.37dCVE-2026-83066.1 MED16.5%
——5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS.
This issue affects Access Control System (GKS): before Version 2.54dCVE-2026-57936.1 MED16.5%
——5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS.
This issue affects BiEticaret: before v3.3.57.51dCVE-2026-82542.4 LOW16.5%
——5A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.37dCVE-2023-4163—16.5%
——5——CVE-2023-0969—16.5%
——5——CVE-2021-38967—16.5%
——5——CVE-2021-0478—16.5%
——5——CVE-2024-39463—16.5%
——5——CVE-2026-132346.1 MED16.5%
——5Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS). This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.23dCVE-2013-5762—16.5%
——5——CVE-2026-66920—16.5%
——5Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursively traversed graph edges, while the JSON viewer recursively processed each level of a node’s data structure. A specially crafted graph containing an excessively long path, deeply nested properties, or circular object references could therefore exhaust the JavaScript call stack when Pivotick calculates a layout or displays a node in the inspection modal.
Successful exploitation may cause an uncaught exception, freeze the affected page, or crash the browser tab, resulting in a client-side denial of service. No confidentiality or integrity impact has been identified.
The patch replaces the recursive graph traversals with iterative stack-based implementations and limits the reachability calculation to 1,000,000 edge traversals. It also limits JSON rendering to 64 levels and detects circular references before descending further into an object.30dCVE-2026-22322—16.5%
——5——CVE-2026-32104—16.5%
——5——CVE-2021-33122—16.5%
——5——CVE-2021-33080—16.5%
——5——CVE-2023-6093—16.5%
——5——CVE-2026-21686—16.5%
——5——CVE-2025-65031—16.5%
——5——CVE-2017-2690—16.5%
——5——CVE-2026-24040—16.5%
——5——CVE-2026-510816.1 MED16.5%
——5A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.43dCVE-2026-83106.1 MED16.5%
——5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS.
This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.52dCVE-2026-6782—16.5%
——5——CVE-2026-21687—16.5%
——5——CVE-2026-21691—16.5%
——5——CVE-2025-66373—16.5%
——5——CVE-2025-2150—16.5%
——5——