Vulnerabilities exploitable today
356,659in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,528
- High10,661
- Medium6,811
- Low680
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-3908—8.0%
——2——CVE-2026-3176—8.0%
——2——CVE-2021-34391—8.0%
——2——CVE-2025-40229—8.0%
——2——CVE-2025-12563—8.0%
——2——CVE-2024-26999—8.0%
——2——CVE-2025-40232—8.0%
——2——CVE-2025-12056—8.0%
——2——CVE-2026-40875—8.0%
——2——CVE-2025-69237—8.0%
——2——CVE-2026-178456.1 MED8.0%
——2Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)5dCVE-2023-53784—8.0%
——2——CVE-2025-66085—8.0%
——2——CVE-2024-41811—8.0%
——2——CVE-2023-53787—8.0%
——2——CVE-2024-27817—8.0%
——2——CVE-2025-31162—8.0%
——2——CVE-2025-40255—8.0%
——2——CVE-2025-37786—8.0%
——2——CVE-2025-14290—8.0%
——2——CVE-2020-0110—8.0%
——2——CVE-2023-39984—8.0%
——2——CVE-2025-11172—8.0%
——2——CVE-2023-39985—8.0%
——2——CVE-2023-54138—8.0%
——2——CVE-2025-12038—8.0%
——2——CVE-2024-28951—8.0%
——2——CVE-2025-40247—8.0%
——2——CVE-2022-34355—8.0%
——2——CVE-2026-449036.1 MED8.0%
——2Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram heatmap chart view does not escape le label values when inserting them into the HTML for use as axis tick mark labels. An attacker who can inject crafted metrics can execute JavaScript in the browser of any Prometheus user who views the metric in the heatmap chart UI. This vulnerability is fixed in 3.5.3 and 3.11.3.15dCVE-2023-21395—8.0%
——2——CVE-2025-38328—8.0%
——2——CVE-2025-40234—8.0%
——2——CVE-2026-630956.5 MED8.0%
——2Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership verification. Attackers can exploit the unverified Forget3PID handler to remove a victim's email or MSISDN binding and subsequently rebind the address through an identity server to hijack the victim's password reset flow.22dCVE-2024-29074—8.0%
——2——CVE-2025-61786—8.0%
——2——CVE-2023-3747—8.0%
——2——CVE-2026-25645—8.0%
——2——CVE-2023-54131—8.0%
——2——CVE-2024-39442—8.0%
——2——