Vulnerabilities exploitable today
364,238in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,674
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,604
- High10,664
- Medium5,892
- Low564
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-5754—13.2%
——4——CVE-2022-36877—13.2%
——4——CVE-2026-41189—13.2%
——4——CVE-2019-25394—13.2%
——4——CVE-2024-54119—13.2%
——4——CVE-2023-52873—13.2%
——4——CVE-2024-7400—13.2%
——4——CVE-2026-2431—13.2%
——4——CVE-2021-25433—13.2%
——4——CVE-2026-46427—13.2%
——4——CVE-2025-23765—13.2%
——4——CVE-2025-40887—13.2%
——4——CVE-2020-15496—13.2%
——4——CVE-2022-48845—13.2%
——4——CVE-2024-54104—13.2%
——4——CVE-2026-40834—13.2%
——4——CVE-2025-15374—13.2%
——4——CVE-2025-20279—13.2%
——4——CVE-2024-35794—13.2%
——4——CVE-2019-2306—13.2%
——4——CVE-2026-271366.1 MED13.2%
——4Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.31dCVE-2026-736716.1 MED13.2%
——4Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforcement. Attackers can craft a malicious logout URL containing an arbitrary external domain or javascript: URI scheme to redirect authenticated users to attacker-controlled phishing pages after session destruction, enabling credential theft and OAuth redirect abuse.9dCVE-2026-33368—13.2%
——4——CVE-2025-25009—13.2%
——4——CVE-2026-657098.3 HIG13.2%
——4sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without AccountFilterUser checks to modify or delete accounts beyond the scope of their assigned token permissions.26dCVE-2025-10778—13.2%
——4——CVE-2025-25770—13.2%
——4——CVE-2024-7979—13.2%
——4——CVE-2021-25523—13.2%
——4——CVE-2026-638668.8 HIG13.2%
——4In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()
Clear WCID pointer removing the sta link in mt7996_mac_sta_deinit_link
routine.27dCVE-2019-5295—13.2%
——4——CVE-2024-35773—13.2%
——4——CVE-2026-53840—13.2%
——4——CVE-2021-42855—13.2%
——4——CVE-2026-331017.8 HIG13.2%
——4Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.29dCVE-2024-41262—13.2%
——4——CVE-2022-49529—13.2%
——4——CVE-2025-64375—13.2%
——4——CVE-2021-25674—13.2%
——4——CVE-2026-42742—13.2%
——4——