Vulnerabilities exploitable today
356,780in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,532
- High10,545
- Medium6,712
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-13705—9.1%
——3——CVE-2023-23632—9.1%
——3——CVE-2025-3677—9.1%
——3——CVE-2017-12306—9.1%
——3——CVE-2021-47873—9.1%
——3——CVE-2022-34855—9.1%
——3——CVE-2026-32775—9.1%
——3——CVE-2025-69029—9.1%
——3——CVE-2023-28065—9.1%
——3——CVE-2025-12965—9.1%
——3——CVE-2023-53766—9.1%
——3——CVE-2022-48188—9.1%
——3——CVE-2026-6868—9.1%
——3——CVE-2018-5834—9.1%
——3——CVE-2025-8779—9.1%
——3——CVE-2025-23382—9.1%
——3——CVE-2023-41093—9.1%
——3——CVE-2025-63522—9.1%
——3——CVE-2026-0812—9.1%
——3——CVE-2022-42464—9.1%
——3——CVE-2021-21589—9.1%
——3——CVE-2026-2233—9.1%
——3——CVE-2025-54999—9.1%
——3——CVE-2025-7058—9.1%
——3——CVE-2025-8687—9.1%
——3——CVE-2025-61805—9.1%
——3——CVE-2023-7195—9.1%
——3——CVE-2026-26939—9.1%
——3——CVE-2026-7376—9.1%
——3——CVE-2026-1151—9.1%
——3——CVE-2025-43391—9.1%
——3——CVE-2026-120414.4 MED9.1%
——3The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.33dCVE-2025-31689—9.1%
——3——CVE-2022-49918—9.1%
——3——CVE-2026-37592—9.1%
——3——CVE-2026-182173.4 LOW9.1%
——3A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.3dCVE-2025-363598.1 HIG9.1%
——3IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.35dCVE-2025-40110—9.1%
——3——CVE-2022-49915—9.1%
——3——CVE-2025-61803—9.1%
——3——