Vulnerabilities exploitable today
356,768in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,533
- High10,540
- Medium6,708
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-48571—8.9%
——3——CVE-2026-396805.3 MED8.9%
——3Missing Authorization vulnerability in MWP Development Diet Calorie Calculator diet-calorie-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Diet Calorie Calculator: from n/a through <= 1.1.1.16dCVE-2026-449646.5 MED8.9%
——3In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-controlled Intent extras, including a full-screen lock-screen message, an arbitrary on-call page ID, and an arbitrary Intent to run inside the Datadog process.
This requires:
A malicious application co-installed on the victim's device.
An active Datadog session in the Android app.
Impact: After a single tap on the Acknowledge button, the app sends a forged on-call acknowledgement to the backend under the victim's session, launches the attacker-supplied Intent from within the Datadog process (reaching otherwise non-exported components), and turns on the screen while dismissing the keyguard.2dCVE-2018-11273—8.9%
——3——CVE-2025-59335—8.9%
——3——CVE-2025-562935.4 MED8.9%
——3code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Information section in the Childs Name field.36dCVE-2025-58265—8.9%
——3——CVE-2017-15855—8.9%
——3——CVE-2024-35192—8.8%
——3——CVE-2026-25100—8.9%
——3——CVE-2026-75437.2 HIG8.8%
——3The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.23dCVE-2025-58917—8.9%
——3——CVE-2015-6643—8.9%
——3——CVE-2025-53488—8.9%
——3——CVE-2025-31068—8.9%
——3——CVE-2025-57996—8.9%
——3——CVE-2025-30300—8.9%
——3——CVE-2026-8143—8.8%
——3——CVE-2025-53865—8.9%
——3——CVE-2025-60147—8.9%
——3——CVE-2025-52620—8.9%
——3——CVE-2019-9386—8.9%
——3——CVE-2022-46359—8.9%
——3——CVE-2025-57993—8.9%
——3——CVE-2016-10398—8.9%
——3——CVE-2025-58028—8.9%
——3——CVE-2025-9989—8.9%
——3——CVE-2025-68861—8.9%
——3——CVE-2026-7998—8.9%
——3——CVE-2026-44558—8.9%
——3——CVE-2025-45585—8.9%
——3——CVE-2025-31639—8.9%
——3——CVE-2025-36563—8.9%
——3——CVE-2025-53482—8.9%
——3——CVE-2016-2457—8.9%
——3——CVE-2025-58242—8.9%
——3——CVE-2025-62930—8.9%
——3——CVE-2026-179724.3 MED8.9%
——3Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)6dCVE-2022-46358—8.9%
——3——CVE-2025-62948—8.9%
——3——