Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,337
- High10,008
- Medium4,921
- Low461
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-14394—14.4%
——4——CVE-2019-25063—14.4%
——4——CVE-2025-57894—14.4%
——4——CVE-2024-45475—14.4%
——4——CVE-2025-49052—14.4%
——4——CVE-2026-44489—14.4%
——4——CVE-2024-45467—14.4%
——4——CVE-2025-9720—14.4%
——4——CVE-2024-13071—14.4%
——4——CVE-2025-58824—14.4%
——4——CVE-2024-54116—14.3%
——4——CVE-2023-20097—14.4%
——4——CVE-2024-49961—14.4%
——4——CVE-2025-2861—14.4%
——4——CVE-2024-49871—14.4%
——4——CVE-2025-32920—14.4%
——4——CVE-2022-48971—14.4%
——4——CVE-2024-54108—14.3%
——4——CVE-2023-432788.8 HIG14.4%
——4A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.50dCVE-2022-48958—14.4%
——4——CVE-2024-50093—14.4%
——4——CVE-2021-33715—14.4%
——4——CVE-2023-52803—14.4%
——4——CVE-2024-53878—14.4%
——4——CVE-2025-59551—14.4%
——4——CVE-2024-53131—14.4%
——4——CVE-2026-139844.3 MED14.4%
——4Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)56dCVE-2026-6863—14.4%
——4——CVE-2025-58594—14.4%
——4——CVE-2026-414558.5 HIG14.4%
——4WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL scheme field accepts any string without protocol restriction or destination validation. Attackers who can create or modify integrations can set webhook URLs to internal network addresses, causing the server to issue HTTP POST requests to attacker-controlled internal targets with full board event payloads, and can additionally exploit response handling to overwrite arbitrary comment text without authorization checks.44dCVE-2025-53343—14.4%
——4——CVE-2026-6042—14.4%
——4——CVE-2026-49110—14.4%
——4——CVE-2026-141104.3 MED14.4%
——4Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)56dCVE-2024-53230—14.4%
——4——CVE-2023-41086—14.4%
——4——CVE-2025-12742—14.4%
——4——CVE-2022-49020—14.4%
——4——CVE-2026-33907—14.4%
——4——CVE-2024-27195—14.4%
——4——