Vulnerabilities exploitable today
356,708in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,545
- High10,617
- Medium6,752
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1911—8.5%
——3——CVE-2025-37773—8.5%
——3——CVE-2026-8873—8.5%
——3——CVE-2026-8703—8.5%
——3——CVE-2023-41971—8.5%
——3——CVE-2025-46158—8.5%
——3——CVE-2026-15283—8.5%
——3——CVE-2024-21774—8.5%
——3——CVE-2024-37469—8.5%
——3——CVE-2024-38877—8.5%
——3——CVE-2026-8701—8.5%
——3——CVE-2025-10179—8.5%
——3——CVE-2023-53754—8.5%
——3——CVE-2026-6517—8.5%
——3——CVE-2019-25558—8.5%
——3——CVE-2024-8037—8.5%
——3——CVE-2021-479506.4 MED8.5%
——3Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated attackers to inject malicious scripts by manipulating the s_emotion parameter. Attackers can submit POST requests to admin.php with JavaScript code in the s_emotion field, which executes when administrators view the smilies tab.20dCVE-2022-49740—8.5%
——3——CVE-2024-21808—8.5%
——3——CVE-2025-40102—8.5%
——3——CVE-2021-479826.4 MED8.5%
——3WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the preset parameter. Attackers can submit POST requests to the plugin settings page with script payloads in the preset parameter that are stored and executed when administrators view the settings.17dCVE-2026-8048—8.5%
——3——CVE-2026-53473—8.5%
——3——CVE-2026-28509—8.5%
——3——CVE-2021-35486—8.5%
——3——CVE-2025-67986—8.5%
——3——CVE-2024-6356—8.5%
——3——CVE-2024-21979—8.5%
——3——CVE-2026-4920—8.5%
——3——CVE-2023-21281—8.5%
——3——CVE-2026-5715—8.5%
——3——CVE-2026-151148.8 HIG8.5%
——3Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)30dCVE-2026-8845—8.5%
——3——CVE-2026-8871—8.5%
——3——CVE-2026-41298—8.5%
——3——CVE-2026-27600—8.5%
——3——CVE-2021-479266.4 MED8.5%
——3Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in users access the form management page, enabling session hijacking or credential theft.15dCVE-2025-43318—8.5%
——3——CVE-2024-50377—8.5%
——3——CVE-2026-28895—8.5%
——3——