Vulnerabilities exploitable today
358,921in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,708
- High11,664
- Medium7,446
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-8158—9.9%
——3——CVE-2026-90248.7 HIG9.9%
——3A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session.22dCVE-2025-64873—9.9%
——3——CVE-2026-20260—9.9%
——3——CVE-2025-64563—9.9%
——3——CVE-2025-64857—9.9%
——3——CVE-2019-14130—9.9%
——3——CVE-2026-712368.7 HIG9.9%
——3Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing &lt;, &gt;, and &amp; back to <, >, and & immediately after purification.3dCVE-2025-0033—9.9%
——3——CVE-2025-64875—9.9%
——3——CVE-2025-64853—9.9%
——3——CVE-2026-34341—9.9%
——3——CVE-2020-9096—9.9%
——3——CVE-2021-1931—9.9%
——3——CVE-2026-32413—9.9%
——3——CVE-2022-50635—9.9%
——3——CVE-2025-64817—9.9%
——3——CVE-2025-64553—9.9%
——3——CVE-2022-36416—9.9%
——3——CVE-2026-2851—9.9%
——3——CVE-2025-11161—9.9%
——3——CVE-2025-46713—9.9%
——3——CVE-2025-30963—9.9%
——3——CVE-2026-22727—9.9%
——3——CVE-2026-41350—9.9%
——3——CVE-2020-11164—9.9%
——3——CVE-2023-29504—9.9%
——3——CVE-2025-11160—9.9%
——3——CVE-2026-56236.3 MED9.9%
——3A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.20dCVE-2026-32396—9.9%
——3——CVE-2025-23148—9.9%
——3——CVE-2026-45348—9.9%
——3——CVE-2025-40181—9.9%
——3——CVE-2026-447466.1 MED9.9%
——3Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL that embeds a malicious script. If a victim clicks this link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim's browser. This could allow the attacker to access and/or modify information related to the webclient, impacting the confidentiality and integrity of the application, with no impact to availability.21dCVE-2023-51711—9.9%
——3——CVE-2026-25428—9.9%
——3——CVE-2025-30961—9.9%
——3——CVE-2025-64833—9.9%
——3——CVE-2024-0109—9.9%
——3——CVE-2019-14100—9.9%
——3——