Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,672
- High11,518
- Medium7,234
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-58607—10.6%
——3——CVE-2025-58620—10.6%
——3——CVE-2025-15345—10.6%
——3——CVE-2018-13885—10.6%
——3——CVE-2021-22571—10.6%
——3——CVE-2025-48316—10.6%
——3——CVE-2026-159667.5 HIG10.6%
——3Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.14dCVE-2024-57178—10.6%
——3——CVE-2026-7437—10.6%
——3——CVE-2022-509586.1 MED10.6%
——3WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers.20dCVE-2025-61645—10.6%
——3——CVE-2025-66594—10.6%
——3——CVE-2025-58823—10.6%
——3——CVE-2023-35699—10.6%
——3——CVE-2025-10729—10.6%
——3The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free.15dCVE-2026-354666.1 MED10.6%
——3XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services20dCVE-2021-32577—10.6%
——3——CVE-2025-23871—10.6%
——3——CVE-2026-41687—10.6%
——3——CVE-2022-30741—10.6%
——3——CVE-2026-628927.0 HIG10.6%
——3Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.1dCVE-2026-627497.0 HIG10.6%
——3Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.1dCVE-2026-657837.0 HIG10.6%
——3Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.1dCVE-2026-627257.0 HIG10.6%
——3Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.1dCVE-2026-10729—10.6%
——3An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.
This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.22dCVE-2026-627737.0 HIG10.6%
——3Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.1dCVE-2025-58610—10.6%
——3——CVE-2021-40854—10.6%
——3——CVE-2025-23861—10.6%
——3——CVE-2025-23808—10.6%
——3——CVE-2025-23832—10.6%
——3——CVE-2025-23895—10.6%
——3——CVE-2025-23815—10.6%
——3——CVE-2025-9308—10.6%
——3——CVE-2025-58618—10.6%
——3——CVE-2025-58851—10.6%
——3——CVE-2025-23822—10.6%
——3——CVE-2024-2970—10.6%
——3——CVE-2018-11976—10.6%
——3——CVE-2022-4894—10.6%
——3——