Vulnerabilities exploitable today
356,740in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,546
- High10,615
- Medium6,754
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-9160—8.6%
——3——CVE-2026-2209—8.6%
——3——CVE-2025-54465—8.6%
——3——CVE-2026-585987.0 HIG8.6%
——3Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.18dCVE-2019-10566—8.6%
——3——CVE-2025-33099—8.6%
——3——CVE-2024-41780—8.6%
——3——CVE-2022-49594—8.6%
——3——CVE-2025-15466—8.6%
——3——CVE-2023-53056—8.6%
——3——CVE-2026-25034—8.6%
——3——CVE-2024-53682—8.6%
——3——CVE-2024-9495—8.6%
——3——CVE-2025-40265—8.6%
——3——CVE-2026-447433.7 LOW8.6%
——3Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information .This has a low impact on the confidentiality of the data. There is no impact on integrity and availability of the application.17dCVE-2024-7021—8.6%
——3——CVE-2026-140794.3 MED8.6%
——3Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)39dCVE-2024-235649.1 CRI8.6%
——3HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.23dCVE-2019-25584—8.6%
——3——CVE-2025-563046.1 MED8.6%
——3Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.36dCVE-2024-5684—8.6%
——3——CVE-2026-28274.7 MED8.6%
——3The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notification' parameter in versions up to, and including, 1.4.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.17dCVE-2026-146145.4 MED8.6%
——3A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.4dCVE-2026-42640—8.6%
——3——CVE-2025-34396—8.6%
——3——CVE-2023-53061—8.6%
——3——CVE-2026-20063—8.6%
——3——CVE-2024-56550—8.6%
——3——CVE-2024-45354—8.6%
——3——CVE-2022-34755—8.6%
——3——CVE-2025-61431—8.6%
——3——CVE-2026-334152.7 LOW8.6%
——3Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from categories they were not authorized to view. Insufficient access controls on a sentiment analytics endpoint allowed category permission boundaries to be bypassed. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.16dCVE-2026-573727.2 HIG8.6%
——3Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.27dCVE-2023-53813—8.6%
——3——CVE-2024-31943—8.6%
——3——CVE-2023-42774—8.6%
——3——CVE-2023-54267—8.6%
——3——CVE-2019-10555—8.6%
——3——CVE-2019-10498—8.6%
——3——CVE-2024-57492—8.6%
——3——