Vulnerabilities exploitable today
356,708in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,545
- High10,617
- Medium6,752
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-8873—8.5%
——3——CVE-2025-37773—8.5%
——3——CVE-2026-6237—8.5%
——3——CVE-2026-0901—8.5%
——3——CVE-2026-8703—8.5%
——3——CVE-2023-41971—8.5%
——3——CVE-2026-1911—8.5%
——3——CVE-2026-41511—8.5%
——3——CVE-2024-27858—8.5%
——3——CVE-2026-28895—8.5%
——3——CVE-2021-479506.4 MED8.5%
——3Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated attackers to inject malicious scripts by manipulating the s_emotion parameter. Attackers can submit POST requests to admin.php with JavaScript code in the s_emotion field, which executes when administrators view the smilies tab.20dCVE-2026-6247—8.5%
——3——CVE-2021-479266.4 MED8.5%
——3Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in users access the form management page, enabling session hijacking or credential theft.15dCVE-2022-49740—8.5%
——3——CVE-2025-43318—8.5%
——3——CVE-2026-27600—8.5%
——3——CVE-2021-479826.4 MED8.5%
——3WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the preset parameter. Attackers can submit POST requests to the plugin settings page with script payloads in the preset parameter that are stored and executed when administrators view the settings.17dCVE-2024-21808—8.5%
——3——CVE-2026-568096.1 MED8.5%
——3Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL.31dCVE-2025-40102—8.5%
——3——CVE-2025-7056—8.5%
——3——CVE-2024-50377—8.5%
——3——CVE-2022-35218—8.5%
——3——CVE-2024-31896—8.5%
——3——CVE-2026-12035—8.5%
——3——CVE-2025-49880—8.5%
——3——CVE-2026-42336—8.5%
——3MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsistent DNS resolution between validation and actual request execution, allowing attackers to access internal network services. This vulnerability is fixed in 2.8.1.17dCVE-2026-7661—8.5%
——3——CVE-2021-47507—8.5%
——3——CVE-2026-8040—8.5%
——3——CVE-2020-1848—8.5%
——3——CVE-2018-252396.2 MED8.5%
——3Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that crashes the application.19dCVE-2019-14092—8.5%
——3——CVE-2026-20141—8.5%
——3——CVE-2026-6921—8.5%
——3——CVE-2008-0580—8.4%
——3——CVE-2026-23092—8.4%
——3——CVE-2018-3564—8.4%
——3——CVE-2022-49855—8.4%
——3——CVE-2024-34682—8.4%
——3——