Vulnerabilities exploitable today
356,750in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,533
- High10,541
- Medium6,704
- Low664
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-24555—8.8%
——3——CVE-2025-14758—8.8%
——3——CVE-2022-49881—8.8%
——3——CVE-2022-49836—8.8%
——3——CVE-2019-10503—8.8%
——3——CVE-2021-26371—8.8%
——3——CVE-2026-479835.4 MED8.8%
——3Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.20dCVE-2025-11274—8.8%
——3——CVE-2024-33658—8.8%
——3——CVE-2025-43336—8.8%
——3——CVE-2026-479865.4 MED8.8%
——3Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.17dCVE-2026-26059—8.8%
——3——CVE-2023-29144—8.8%
——3——CVE-2026-21298—8.8%
——3——CVE-2026-5276—8.8%
——3——CVE-2026-580456.2 MED8.8%
——3A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.
Repeated exploitation of this condition can result in a denial of service.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.5dCVE-2026-54359—8.8%
——3——CVE-2025-12278—8.8%
——3——CVE-2026-479825.4 MED8.8%
——3Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.17dCVE-2022-49794—8.8%
——3——CVE-2026-479875.4 MED8.8%
——3Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.17dCVE-2024-58018—8.8%
——3——CVE-2024-33509—8.8%
——3——CVE-2026-566664.8 MED8.8%
——3ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the same email before auto-linking by email, allowing a permissive provider account with a victim email address to be linked to the victim's local account. This issue is fixed in version 4.15.3.27dCVE-2026-164427.4 HIG8.8%
——3A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.3dCVE-2026-64285—8.8%
——3In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Pin source page for write when adding CPUID data for SNP guest
When populating a guest_memfd instance with the initial CPUID data for an
SNP guest, acquire a writable pin on the source page as KVM will write back
the "correct" CPUID information if the userspace provided data is rejected
by trusted firmware. Because KVM writes to the source page using a kernel
mapping, pinning for read could result in KVM clobbering read-only memory.
Note, well-behaved VMMs are unlikely to be affected, as CPUID information
is almost always dynamically generated by userspace, i.e. it's unlikely for
the CPUID information to be backed by a read-only mapping.
[sean: rewrite shortlog and changelog, tag for stable@]10dCVE-2026-625256.3 MED8.8%
——3Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Quality accessible data as well as unauthorized read access to a subset of Oracle Quality accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Quality. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).17dCVE-2019-10517—8.8%
——3——CVE-2025-21728—8.8%
——3——CVE-2023-44300—8.8%
——3——CVE-2026-25460—8.8%
——3——CVE-2024-57510—8.8%
——3——CVE-2024-39846—8.8%
——3——CVE-2026-482685.4 MED8.8%
——3Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.17dCVE-2022-49841—8.8%
——3——CVE-2022-49835—8.8%
——3——CVE-2019-10584—8.8%
——3——CVE-2026-8535—8.8%
——3——CVE-2019-2319—8.8%
——3——CVE-2024-31088—8.8%
——3——