Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,405
- High10,145
- Medium5,058
- Low466
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-67752—14.0%
——4——CVE-2026-21295—14.0%
——4——CVE-2026-140804.3 MED14.0%
——4Insufficient validation of untrusted input in TabSwitcher in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Low)51dCVE-2021-47256—14.0%
——4——CVE-2024-43180—14.0%
——4——CVE-2025-59745—14.0%
——4——CVE-2026-55724.3 MED14.0%
——4A security flaw has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.33dCVE-2025-52741—14.0%
——4——CVE-2022-20334—14.0%
——4——CVE-2025-52763—14.0%
——4——CVE-2022-48355—14.0%
——4——CVE-2018-10988—14.0%
——4——CVE-2023-27899—14.0%
——4——CVE-2026-0038—14.0%
——4——CVE-2025-2347—14.0%
——4——CVE-2025-49963—14.0%
——4——CVE-2019-19754—14.0%
——4——CVE-2024-50186—14.0%
——4——CVE-2021-36325—14.0%
——4——CVE-2024-39734—14.0%
——4——CVE-2011-4212—14.0%
——4——CVE-2023-5088—14.0%
——4——CVE-2025-63879—14.0%
——4——CVE-2025-49957—14.0%
——4——CVE-2025-66058—14.0%
——4——CVE-2020-14365—14.0%
——4——CVE-2025-53352—14.0%
——4——CVE-2021-3848—14.0%
——4——CVE-2021-47872—14.0%
——4——CVE-2017-18332—14.0%
——4——CVE-2026-80456.5 MED14.0%
——4CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.37dCVE-2025-52751—14.0%
——4——CVE-2026-6795—14.0%
——4——CVE-2022-22444—14.0%
——4——CVE-2025-52770—14.0%
——4——CVE-2026-6991—14.0%
——4——CVE-2022-26743—14.0%
——4——CVE-2025-53351—14.0%
——4——CVE-2026-141882.7 LOW14.0%
——4The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.16dCVE-2023-3180—14.0%
——4——