Vulnerabilities exploitable today
359,428in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,495
- High11,159
- Medium7,083
- Low650
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-348076.4 MED10.8%
——3Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.21dCVE-2022-35903—10.8%
——3——CVE-2026-33370—10.8%
——3——CVE-2020-11217—10.8%
——3——CVE-2026-33308—10.8%
——3——CVE-2026-573846.5 MED10.8%
——3Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.22dCVE-2021-47528—10.8%
——3——CVE-2021-47591—10.8%
——3——CVE-2023-20565—10.8%
——3——CVE-2025-1792—10.8%
——3——CVE-2021-47531—10.8%
——3——CVE-2026-41556—10.8%
——3——CVE-2022-48889—10.8%
——3——CVE-2024-32852—10.8%
——3——CVE-2025-12370—10.8%
——3——CVE-2021-47530—10.8%
——3——CVE-2020-11228—10.8%
——3——CVE-2025-21916—10.8%
——3——CVE-2025-1273—10.8%
——3——CVE-2025-15511—10.8%
——3——CVE-2021-47524—10.8%
——3——CVE-2021-47526—10.8%
——3——CVE-2021-47529—10.8%
——3——CVE-2024-0123—10.8%
——3——CVE-2023-31022—10.8%
——3——CVE-2025-30102—10.8%
——3——CVE-2024-0156—10.8%
——3——CVE-2022-50551—10.8%
——3——CVE-2023-40222—10.8%
——3——CVE-2022-35902—10.8%
——3——CVE-2020-25160—10.8%
——3——CVE-2024-50192—10.8%
——3——CVE-2024-1188—10.8%
——3——CVE-2022-50636—10.8%
——3——CVE-2026-139864.2 MED10.7%
——3Inappropriate implementation in Media UI in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)43dCVE-2026-42390—10.7%
——3——CVE-2024-28883—10.7%
——3——CVE-2025-63033—10.7%
——3——CVE-2023-38531—10.7%
——3——CVE-2023-3359—10.7%
——3——