Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,289
- High9,343
- Medium5,276
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-64634—16.3%
——5——CVE-2026-90297.3 HIG16.3%
——5A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).50dCVE-2025-46859—16.3%
——5——CVE-2025-46475—16.3%
——5——CVE-2025-46445—16.3%
——5——CVE-2025-26952—16.3%
——5——CVE-2026-32354—16.3%
——5——CVE-2024-38630—16.3%
——5——CVE-2025-14798—16.3%
——5——CVE-2024-431136.1 MED16.3%
——5The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.10dCVE-2026-484957.1 HIG16.3%
——5TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptographic integrity protection or authorization checks. The callback route is authenticated, but it does not verify that the authenticated user has write access to the target workspace or Typebot before creating credentials in the workspace or updating Typebot groups. An authenticated user who can obtain a valid Google OAuth `code` can alter the `state` value to create Google Sheets credentials in another workspace and, if target IDs are known, attach those credentials to a block in another Typebot. Version 3.17.0 patches the issue.16dCVE-2021-47885—16.3%
——5——CVE-2018-11845—16.3%
——5——CVE-2025-46875—16.3%
——5——CVE-2026-42082—16.3%
——5——CVE-2022-49033—16.3%
——5——CVE-2021-29892—16.3%
——5——CVE-2026-24900—16.3%
——5——CVE-2024-431126.1 MED16.3%
——5Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.10dCVE-2026-24032—16.3%
——5——CVE-2025-46873—16.3%
——5——CVE-2026-32724—16.3%
——5——CVE-2025-46851—16.3%
——5——CVE-2025-54032—16.3%
——5——CVE-2025-11196—16.3%
——5——CVE-2021-33107—16.3%
——5——CVE-2023-52742—16.3%
——5——CVE-2026-456537.0 HIG16.3%
——5Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.38dCVE-2025-46476—16.3%
——5——CVE-2023-24592—16.3%
——5——CVE-2026-567204.3 MED16.3%
——5CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that allows any authenticated user to access any other user's profile data by supplying an arbitrary user ID parameter. Attackers can send a GET request to the admin profile endpoint with an enumerable sequential integer user ID to disclose profile information of any user, including administrators, due to the profile action being excluded from the role validation filter with no compensating ownership check.18dCVE-2025-46860—16.3%
——5——CVE-2025-26896—16.3%
——5——CVE-2025-46509—16.3%
——5——CVE-2026-32372—16.3%
——5——CVE-2025-46447—16.3%
——5——CVE-2025-26897—16.3%
——5——CVE-2024-28067—16.3%
——5——CVE-2026-187785.3 MED16.3%
——5The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address.10dCVE-2025-54809—16.3%
——5——