Vulnerabilities exploitable today
354,831in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,554
- High9,165
- Medium7,426
- Low692
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-11223—5.8%
——2——CVE-2020-11253—5.8%
——2——CVE-2026-351403.0 LOW5.8%
——2HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.16dCVE-2023-54076—5.8%
——2——CVE-2026-42225—5.8%
——2——CVE-2023-54228—5.8%
——2——CVE-2026-419834.3 MED5.8%
——2DoS vulnerability in the browser kernel. Impact: Successful exploitation of this vulnerability may affect availability.10dCVE-2026-63861—5.8%
——2In the Linux kernel, the following vulnerability has been resolved:
spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback
mtk_snand_probe() registers the on-host NAND ECC engine, but teardown was
missing from both probe unwind and remove-time cleanup. Add a devm cleanup
action after successful registration so
nand_ecc_unregister_on_host_hw_engine() runs automatically on probe
failures and during device removal.5dCVE-2020-11177—5.8%
——2——CVE-2025-0732—5.8%
——2——CVE-2023-29261—5.8%
——2——CVE-2025-85916.1 MED5.8%
——2The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application.
By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.24dCVE-2026-150825.4 MED5.8%
——2Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Site Scripting (XSS). This issue affects Siteimprove Analytics versions: from 0.0.0 to 2.0.1.19dCVE-2026-3706—5.8%
——2——CVE-2023-54291—5.8%
——2——CVE-2026-21333—5.8%
——2——CVE-2023-46669—5.8%
——2——CVE-2020-0271—5.8%
——2——CVE-2025-68187—5.8%
——2——CVE-2025-12168—5.8%
——2——CVE-2025-13954—5.8%
——2——CVE-2018-253975.3 MED5.8%
——2PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that automatically submits POST requests to the users.php endpoint with parameters like name, email, password, and permissions set to admin to create unauthorized admin accounts.12dCVE-2022-38466—5.8%
——2——CVE-2025-55556—5.8%
——2——CVE-2023-53144—5.8%
——2——CVE-2026-45173—5.8%
——2——CVE-2023-54215—5.8%
——2——CVE-2025-68205—5.8%
——2——CVE-2026-447504.3 MED5.8%
——2SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. This could allow a low-privileged user to perform actions that would otherwise be restricted, resulting in escalation of privileges. This has a low impact on integrity, while confidentiality and availability are not impacted.10dCVE-2020-11204—5.8%
——2——CVE-2024-7346—5.8%
——2——CVE-2023-48684—5.8%
——2——CVE-2026-23047—5.8%
——2——CVE-2022-40263—5.8%
——2——CVE-2025-15516—5.8%
——2——CVE-2026-13029—5.8%
——2——CVE-2026-34391—5.8%
——2——CVE-2025-68193—5.8%
——2——CVE-2025-0733—5.8%
——2——CVE-2023-54206—5.8%
——2——