Vulnerabilities exploitable today
355,887in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,660
New KEV · 24H0
Exploit Today ≥ 701,604
Distribution · last window
- Critical2,768
- High11,114
- Medium7,337
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-59933—7.4%
——2——CVE-2022-50654—7.4%
——2——CVE-2023-53789—7.4%
——2——CVE-2026-8559—7.4%
——2——CVE-2024-2105—7.4%
——2——CVE-2025-21978—7.4%
——2——CVE-2023-53121—7.4%
——2——CVE-2026-39309—7.4%
——2——CVE-2025-24363—7.4%
——2——CVE-2023-30712—7.4%
——2——CVE-2025-9457—7.4%
——2——CVE-2025-62091—7.3%
——2——CVE-2026-584504.3 MED7.3%
——2Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting a malicious value into the intended query parameter. Attackers can craft a client login link with an external URL in the intended parameter, which is stored in the session without host validation and emitted verbatim via a bare redirect in the ContactLoginController authenticated() handler after the victim completes a legitimate login, enabling phishing attacks.22dCVE-2025-12151—7.3%
——2——CVE-2022-49926—7.3%
——2——CVE-2025-62756—7.3%
——2——CVE-2025-63021—7.3%
——2——CVE-2025-10018—7.3%
——2——CVE-2026-111924.3 MED7.3%
——2Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Medium)14dCVE-2025-27087—7.3%
——2——CVE-2022-35640—7.3%
——2——CVE-2025-15469—7.3%
——2——CVE-2021-47128—7.3%
——2——CVE-2025-66146—7.3%
——2——CVE-2025-12645—7.3%
——2——CVE-2025-23050—7.3%
——2——CVE-2018-5864—7.3%
——2——CVE-2026-24847—7.3%
——2——CVE-2025-66145—7.3%
——2——CVE-2026-34446—7.3%
——2——CVE-2026-110326.5 MED7.3%
——2Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)14dCVE-2025-11859—7.3%
——2——CVE-2025-68275—7.3%
——2——CVE-2025-11860—7.3%
——2——CVE-2026-35346—7.3%
——2——CVE-2025-15395—7.3%
——2——CVE-2025-62888—7.3%
——2——CVE-2026-3215—7.3%
——2——CVE-2026-111766.5 MED7.3%
——2Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)14dCVE-2025-20206—7.3%
——2——