Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,296
- High9,357
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-5283—16.4%
——5——CVE-2024-45828—16.4%
——5——CVE-2026-23840—16.4%
——5——CVE-2022-509656.1 MED16.4%
——5uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.37dCVE-2022-509626.1 MED16.4%
——5uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.37dCVE-2023-52838—16.4%
——5——CVE-2025-62082—16.4%
——5——CVE-2025-66803—16.4%
——5——CVE-2025-30969—16.4%
——5——CVE-2026-40743—16.4%
——5——CVE-2026-12310—16.4%
——5——CVE-2025-28969—16.4%
——5——CVE-2025-30259—16.4%
——5——CVE-2023-5597—16.4%
——5——CVE-2022-509646.1 MED16.4%
——5uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.37dCVE-2026-329945.3 MED16.4%
——5The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, direct messages, channels) by simply providing the target message ID. The endpoint fetches the message via Messages.findOneById(messageId) with no room access check (canAccessRoomIdAsync is never called), returning the complete IMessage object including message text, sender info, room ID, timestamps, and markdown content.37dCVE-2026-20748—16.4%
——5——CVE-2023-52844—16.4%
——5——CVE-2025-63687—16.4%
——5——CVE-2025-40892—16.4%
——5——CVE-2023-47384—16.4%
——5——CVE-2025-39486—16.4%
——5——CVE-2024-36959—16.4%
——5——CVE-2025-2149—16.4%
——5——CVE-2024-57969—16.4%
——5——CVE-2024-4744—16.4%
——5——CVE-2025-3223—16.4%
——5——CVE-2026-12312—16.4%
——5——CVE-2026-167134.3 MED16.4%
——5IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address.12dCVE-2026-33447—16.4%
——5——CVE-2025-2279—16.4%
——5——CVE-2025-14052—16.4%
——5——CVE-2025-691567.1 HIG16.4%
——5Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.58dCVE-2026-574037.1 HIG16.4%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Security Headers gd-security-headers allows Reflected XSS.This issue affects GD Security Headers: from n/a through <= 1.8.47dCVE-2025-6664—16.4%
——5——CVE-2026-57333—16.4%
——5——CVE-2025-68896—16.4%
——5——CVE-2022-3894—16.4%
——5——CVE-2026-655117.1 HIG16.4%
——5Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.37dCVE-2026-57337—16.4%
——5——