Vulnerabilities exploitable today
356,679in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,534
- High10,642
- Medium6,742
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-49964—8.1%
——2——CVE-2024-33396—8.1%
——2——CVE-2024-31109—8.1%
——2——CVE-2025-12086—8.1%
——2——CVE-2026-56376—8.1%
——2——CVE-2022-50037—8.1%
——2——CVE-2023-32554—8.1%
——2——CVE-2017-18330—8.1%
——2——CVE-2023-53710—8.1%
——2——CVE-2025-2762—8.1%
——2——CVE-2019-25315—8.1%
——2——CVE-2024-51223—8.1%
——2——CVE-2025-62845—8.1%
——2——CVE-2022-42277—8.1%
——2——CVE-2024-0245—8.1%
——2——CVE-2025-12169—8.1%
——2——CVE-2026-655177.1 HIG8.1%
——2Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.2dCVE-2025-25334—8.1%
——2——CVE-2025-38324—8.1%
——2——CVE-2025-12751—8.1%
——2——CVE-2026-42180—8.1%
——2——CVE-2025-23179—8.1%
——2——CVE-2026-177285.4 MED8.1%
——2Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)9dCVE-2023-32555—8.1%
——2——CVE-2026-24433—8.1%
——2——CVE-2026-53536—8.1%
——2Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing secret but did not check the token's audience, and combined with a missing null-check on the decoded fileId, this allowed any caller holding any valid Activepieces JWT (including a freshly created user's own access token) to receive a step-file belonging to another tenant. The file returned was whatever PostgreSQL happened to scan first for type = FLOW_STEP_FILE, varying over time as the database changed, so an authenticated user could obtain step-file attachments belonging to other tenants on the same instance; the attacker could not target a specific victim or file, and the access was read-only with no integrity or availability impact. This issue is fixed in version 0.83.0.22dCVE-2023-0221—8.1%
——2——CVE-2024-31154—8.1%
——2——CVE-2025-4294—8.1%
——2——CVE-2026-503617.8 HIG8.1%
——2Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.17dCVE-2025-12022—8.1%
——2——CVE-2024-21801—8.1%
——2——CVE-2025-12577—8.1%
——2——CVE-2026-667015.3 MED8.1%
——2Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.20hCVE-2021-39670—8.1%
——2——CVE-2025-68331—8.1%
——2——CVE-2022-50016—8.1%
——2——CVE-2024-25630—8.1%
——2——CVE-2026-454877.8 HIG8.1%
——2Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.17dCVE-2026-666995.3 MED8.1%
——2Custom role Broken Access Control in Dokan <= 5.0.10 versions.2d