Vulnerabilities exploitable today
356,679in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,534
- High10,642
- Medium6,742
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-3634—8.2%
——2——CVE-2026-22342—8.2%
——2——CVE-2026-2919—8.2%
——2——CVE-2026-262147.4 HIG8.2%
——2Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by default in FDSClientConfiguration, all applications using the SDK with default settings are affected. This vulnerability allows a man-in-the-middle attacker to intercept and modify SDK communications to Xiaomi FDS cloud storage endpoints, potentially exposing authentication credentials, file contents, and API responses. The XiaoMi/galaxy-fds-sdk-android open source project has reached end-of-life status.25dCVE-2025-67639—8.2%
——2——CVE-2023-30440—8.2%
——2——CVE-2023-3116—8.2%
——2——CVE-2025-43929—8.2%
——2——CVE-2024-45417—8.2%
——2——CVE-2023-54014—8.2%
——2——CVE-2019-25316—8.2%
——2——CVE-2026-116938.1 HIG8.2%
——2Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)17dCVE-2023-20943—8.2%
——2——CVE-2023-54283—8.2%
——2——CVE-2025-43371—8.2%
——2——CVE-2025-258257.1 HIG8.2%
——2A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section.35dCVE-2018-12014—8.2%
——2——CVE-2025-71241—8.2%
——2——CVE-2018-11962—8.2%
——2——CVE-2023-54005—8.2%
——2——CVE-2023-53649—8.2%
——2——CVE-2025-8075—8.2%
——2——CVE-2023-36838—8.2%
——2——CVE-2025-68517—8.2%
——2——CVE-2026-667015.3 MED8.1%
——2Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.20hCVE-2022-50016—8.1%
——2——CVE-2026-454877.8 HIG8.1%
——2Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.17dCVE-2024-21801—8.1%
——2——CVE-2021-39670—8.1%
——2——CVE-2025-12577—8.1%
——2——CVE-2024-25630—8.1%
——2——CVE-2026-648807.1 HIG8.1%
——2Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.17dCVE-2024-38864—8.1%
——2——CVE-2023-4029—8.1%
——2——CVE-2024-2313—8.1%
——2——CVE-2025-68331—8.1%
——2——CVE-2022-50037—8.1%
——2——CVE-2026-56376—8.1%
——2——CVE-2024-51223—8.1%
——2——CVE-2023-32554—8.1%
——2——