Vulnerabilities exploitable today
354,835in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,555
- High9,167
- Medium7,427
- Low691
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-32124—5.8%
——2——CVE-2023-53126—5.8%
——2——CVE-2026-98244.3 MED5.8%
——2Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command autocomplete.. Mattermost Advisory ID: MMSA-2026-0067619dCVE-2025-0327—5.8%
——2——CVE-2025-34297—5.8%
——2KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platforms where size_t is 32-bit. The nfft parameter is not validated before being used in a size calculation (sizeof(kiss_fft_cpx) * (nfft - 1)), which can wrap to a small value when nfft is large. As a result, malloc() allocates an undersized buffer and the subsequent twiddle-factor initialization loop writes nfft elements, causing a heap buffer overflow. This vulnerability only affects 32-bit architectures.18dCVE-2026-476945.4 MED5.8%
——2WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_description as raw HTML in the Gallery view. A user who can create or edit categories can store JavaScript in a category description, which executes when another user views the affected Gallery/category page. This is a stored XSS in the category description field, separate from previously fixed XSS issues in video titles or comments.12dCVE-2026-21003—5.8%
——2——CVE-2025-69284—5.8%
——2——CVE-2026-21306—5.8%
——2——CVE-2022-38083—5.8%
——2——CVE-2025-21820—5.8%
——2——CVE-2026-54025—5.8%
——2——CVE-2020-37060—5.8%
——2——CVE-2021-35102—5.8%
——2——CVE-2026-393805.4 MED5.8%
——2Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations configuration feature. The application fails to properly sanitize user input supplied through the stock_location parameter, allowing attackers to inject malicious JavaScript code that is stored in the database and executed when rendered in the Employees interface. This vulnerability is fixed in 3.4.3.8dCVE-2026-23893—5.8%
——2——CVE-2026-4202—5.8%
——2——CVE-2026-21431—5.8%
——2——CVE-2025-23397—5.8%
——2——CVE-2026-389315.4 MED5.8%
——2A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.28dCVE-2026-41156—5.8%
——2——CVE-2025-697524.3 MED5.8%
——2An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.28dCVE-2026-21432—5.8%
——2——CVE-2026-67935.4 MED5.8%
——2Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS.
This issue affects Q-smart NexT Poll: before 1.8.7.12dCVE-2025-0732—5.8%
——2——CVE-2023-29261—5.8%
——2——CVE-2023-54291—5.8%
——2——CVE-2026-3706—5.8%
——2——CVE-2026-21333—5.8%
——2——CVE-2023-46669—5.8%
——2——CVE-2025-85916.1 MED5.8%
——2The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application.
By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.24dCVE-2022-48683—5.8%
——2——CVE-2025-8894—5.8%
——2——CVE-2023-54216—5.8%
——2——CVE-2025-8893—5.8%
——2——CVE-2020-11253—5.8%
——2——CVE-2025-68197—5.8%
——2——CVE-2026-64179—5.8%
——2In the Linux kernel, the following vulnerability has been resolved:
net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
The memory allocated in ipc_protocol_init() is not freed on the error
paths that follow in ipc_imem_init(). Fix that by calling the
corresponding release function ipc_protocol_deinit() in the error path.3dCVE-2020-11606—5.8%
——2——CVE-2019-9290—5.8%
——2——