Vulnerabilities exploitable today
366,910in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,347
- Medium5,307
- Low510
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-42968—15.8%
——5——CVE-2026-52206.4 MED15.8%
——5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS.
This issue affects DivvyDrive: from 4.8.2.23 before v.4.8.3.1.60dCVE-2026-0824—15.8%
——5——CVE-2024-40977—15.8%
——5——CVE-2025-6644—15.8%
——5——CVE-2026-14337—15.8%
——5Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.26dCVE-2020-9930—15.8%
——5——CVE-2026-4982—15.8%
——5——CVE-2026-2244—15.8%
——5——CVE-2025-15380—15.8%
——5——CVE-2026-54396—15.8%
——5——CVE-2026-78195—15.8%
——5A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's browser.2dCVE-2024-11876—15.8%
——5——CVE-2022-50767—15.8%
——5——CVE-2024-12326—15.8%
——5——CVE-2025-10999—15.8%
——5——CVE-2025-53641—15.8%
——5——CVE-2025-8765—15.8%
——5——CVE-2021-47321—15.8%
——5——CVE-2019-25350—15.8%
——5——CVE-2025-62090—15.8%
——5——CVE-2026-599215.7 MED15.8%
——5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\r\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.23dCVE-2022-32946—15.8%
——5——CVE-2025-42974—15.8%
——5——CVE-2025-67546—15.8%
——5——CVE-2025-20355—15.8%
——5——CVE-2021-47357—15.8%
——5——CVE-2025-1773—15.8%
——5——CVE-2026-763548.1 HIG15.8%
——5In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect system integrity and availability by sending a crafted Representational State Transfer (REST) API request that deletes or temporarily overwrites files writable by the user account running Splunk Enterprise processes on a non-captain search head cluster member. The vulnerability is possible because Search Head Clustering bundle replication does not validate the name of a replicated bundle file or neutralize NUL bytes before constructing the member bundle path. For more information see About search head clustering (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/overview-of-search-head-clustering/about-search-head-clustering), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and Secure Splunk Enterprise service accounts (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.0/install-splunk-enterprise-securely/secure-splunk-enterprise-service-accounts) in the Splunk documentation.9dCVE-2023-48323—15.8%
——5——CVE-2026-59189—15.8%
——5——CVE-2026-4100—15.8%
——5——CVE-2025-52484—15.8%
——5——CVE-2026-5599—15.8%
——5A user with API access and "manage users" permission in any venueless
world is able to trigger deletion of user accounts in other worlds.41dCVE-2026-110858.8 HIG15.8%
——5Integer overflow in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)38dCVE-2025-60319—15.8%
——5——CVE-2024-13301—15.8%
——5——CVE-2024-26997—15.8%
——5——CVE-2025-61839—15.8%
——5——CVE-2024-30145—15.8%
——5——