Vulnerabilities exploitable today
354,882in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,556
- High9,177
- Medium7,435
- Low692
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-660295.4 MED6.2%
——2Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Manage Clients or Manage Client Projects pages where client names are rendered unsanitized.5dCVE-2026-242407.8 HIG6.2%
——2NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.31dCVE-2026-655685.0 MED6.2%
——2Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.6dCVE-2024-56637—6.2%
——2——CVE-2026-132426.5 MED6.2%
——2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.20dCVE-2025-33082—6.2%
——2——CVE-2024-42239—6.2%
——2——CVE-2026-110266.5 MED6.2%
——2Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)11dCVE-2026-27008—6.2%
——2——CVE-2024-54095—6.2%
——2——CVE-2025-58208—6.2%
——2——CVE-2025-20688—6.2%
——2——CVE-2022-0835—6.2%
——2——CVE-2021-1890—6.2%
——2——CVE-2023-2438—6.2%
——2——CVE-2025-12804—6.2%
——2——CVE-2026-413675.0 MED6.2%
——2OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.9dCVE-2026-44473—6.2%
——2——CVE-2018-5895—6.2%
——2——CVE-2026-40458—6.2%
——2——CVE-2025-55074—6.2%
——2——CVE-2019-25548—6.2%
——2——CVE-2019-20574—6.2%
——2——CVE-2025-33083—6.2%
——2——CVE-2026-35363—6.2%
——2——CVE-2019-25551—6.2%
——2——CVE-2026-410734.6 MED6.2%
——2RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is not sanitized before being written to the output file, which can cause spreadsheet applications to interpret crafted values as formulas or macros when the file is opened. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by avoiding opening exported RT spreadsheet files directly in spreadsheet applications when the data may contain untrusted user input.10dCVE-2026-139483.1 LOW6.2%
——2Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)31dCVE-2026-538354.3 MED6.2%
——2OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings without honoring configured config-write controls. Attackers can exploit this by leveraging the dynamic-agent binding feature to change sender-agent binding state beyond intended policy, potentially enabling unauthorized binding modifications.11dCVE-2020-3626—6.2%
——2——CVE-2023-31028—6.2%
——2——CVE-2021-21559—6.2%
——2——CVE-2025-53642—6.2%
——2——CVE-2026-366097.3 HIG6.2%
——2Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from the same source IP. Combined with the predictable XOR-based password encoding (securityEncode function), this allows an attacker to reverse captured authentication tokens to recover the plaintext password.11dCVE-2026-346967.8 HIG6.2%
——2InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.11dCVE-2022-20484—6.2%
——2——CVE-2026-39112—6.2%
——2——CVE-2026-0859—6.2%
——2——CVE-2026-8520—6.2%
——2——CVE-2025-61994—6.2%
——2——