Vulnerabilities exploitable today
356,684in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,537
- High10,637
- Medium6,742
- Low667
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-41374—8.3%
——3——CVE-2026-576707.1 HIG8.3%
——3Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.38dCVE-2026-573437.1 HIG8.3%
——3Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.37dCVE-2022-28635—8.3%
——3——CVE-2024-22346—8.3%
——3——CVE-2025-30585—8.3%
——3——CVE-2024-25905—8.3%
——3——CVE-2025-8154—8.3%
——3——CVE-2024-51102—8.3%
——3——CVE-2023-53617—8.3%
——3——CVE-2026-573587.1 HIG8.3%
——3Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions.38dCVE-2025-64260—8.3%
——3——CVE-2025-68852—8.3%
——3——CVE-2025-30576—8.3%
——3——CVE-2025-6923—8.3%
——3——CVE-2019-10623—8.3%
——3——CVE-2025-30568—8.3%
——3——CVE-2026-573447.1 HIG8.3%
——3Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.38dCVE-2026-399673.1 LOW8.3%
——3TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter results by typebotId, allowing an authenticated user to load result data (user answers, variable values) from a different typebot by supplying a foreign resultId to the startChat endpoint. Exploitation is constrained by CUID2's cryptographically random 24-character IDs (making brute-force infeasible), the requirement that rememberUser be enabled, and the need for matching variable names in the current typebot. If successfully exploited, an attacker can access the original user's previous answers, session variable values, and hasStarted flag, potentially exposing PII like names, emails, and phone numbers. This issue has been fixed in version 3.16.0.17dCVE-2026-22329—8.3%
——3——CVE-2025-30801—8.3%
——3——CVE-2026-144184.3 MED8.3%
——3Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)38dCVE-2026-177436.5 MED8.3%
——3Insufficient policy enforcement in ControlledFrame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)5dCVE-2024-11857—8.3%
——3——CVE-2025-42889—8.3%
——3——CVE-2024-468628.0 HIG8.3%
——3In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: soc-acpi-intel-mtl-match: add missing empty item
There is no links_num in struct snd_soc_acpi_mach {}, and we test
!link->num_adr as a condition to end the loop in hda_sdw_machine_select().
So an empty item in struct snd_soc_acpi_link_adr array is required.5dCVE-2024-6613—8.3%
——3——CVE-2026-576757.1 HIG8.3%
——3Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions.38dCVE-2026-274307.1 HIG8.3%
——3Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.38dCVE-2026-573457.1 HIG8.3%
——3Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.38dCVE-2025-30764—8.3%
——3——CVE-2026-576747.1 HIG8.3%
——3Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions.37dCVE-2024-51106—8.3%
——3——CVE-2025-55278—8.3%
——3——CVE-2025-609568.0 HIG8.3%
——3Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.34dCVE-2026-573517.1 HIG8.3%
——3Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions.38dCVE-2026-488323.5 LOW8.3%
——3action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.16dCVE-2025-20322—8.3%
——3——CVE-2025-68904—8.3%
——3——CVE-2026-573597.1 HIG8.3%
——3Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.38d