Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,707
- High11,613
- Medium7,342
- Low681
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-111326.5 MED10.4%
——3Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)21dCVE-2025-39203—10.4%
——3——CVE-2025-31501—10.4%
——3——CVE-2020-0133—10.4%
——3——CVE-2025-59433—10.3%
——3——CVE-2020-11127—10.3%
——3——CVE-2026-664737.5 HIG10.3%
——3Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.16dCVE-2017-13217—10.3%
——3——CVE-2026-5838—10.3%
——3——CVE-2022-36838—10.3%
——3——CVE-2024-49873—10.3%
——3——CVE-2024-50109—10.3%
——3——CVE-2025-28129—10.3%
——3——CVE-2026-82212.4 LOW10.3%
——3A flaw has been found in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /inventory/item-save. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.20dCVE-2022-48984—10.3%
——3——CVE-2017-17436—10.3%
——3——CVE-2026-162052.4 LOW10.3%
——3A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the argument Info can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.24dCVE-2026-82202.4 LOW10.3%
——3A vulnerability was detected in Devs Palace ERP Online up to 4.0.0. This affects an unknown function of the file /inventory/customer-save. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.20dCVE-2024-56784—10.3%
——3——CVE-2022-49009—10.3%
——3——CVE-2022-48963—10.3%
——3——CVE-2024-35689—10.3%
——3——CVE-2022-49315—10.3%
——3——CVE-2022-49008—10.3%
——3——CVE-2025-1732—10.3%
——3——CVE-2019-14074—10.3%
——3——CVE-2026-4356—10.3%
——3——CVE-2026-3956—10.3%
——3——CVE-2022-49989—10.3%
——3——CVE-2026-41361—10.3%
——3——CVE-2022-50546—10.3%
——3——CVE-2025-13129—10.3%
——3——CVE-2026-82532.4 LOW10.3%
——3A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. Affected by this vulnerability is an unknown functionality of the file /inventory/purchase_save. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.20dCVE-2026-93772.4 LOW10.3%
——3A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.21dCVE-2024-50034—10.3%
——3——CVE-2026-72962.4 LOW10.3%
——3A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument first_name results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used.20dCVE-2026-34324—10.3%
——3——CVE-2025-2819—10.3%
——3——CVE-2026-0954—10.3%
——3——CVE-2026-185924.7 MED10.3%
——3A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.16h