Vulnerabilities exploitable today
354,756in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,619
- High9,379
- Medium7,621
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-20836—5.5%
——2——CVE-2026-7643—5.5%
——2——CVE-2024-47398—5.5%
——2——CVE-2017-13322—5.5%
——2——CVE-2025-37730—5.5%
——2——CVE-2026-133933.5 LOW5.5%
——2The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.18hCVE-2025-28884—5.5%
——2——CVE-2025-28886—5.5%
——2——CVE-2026-133764.8 MED5.5%
——2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071.
This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.23dCVE-2025-26903—5.5%
——2——CVE-2025-14295—5.5%
——2——CVE-2020-0043—5.5%
——2——CVE-2025-39453—5.5%
——2——CVE-2025-41104—5.5%
——2——CVE-2025-29999—5.5%
——2——CVE-2025-28902—5.5%
——2——CVE-2021-22326—5.5%
——2——CVE-2025-28909—5.5%
——2——CVE-2025-22297—5.5%
——2——CVE-2026-110486.5 MED5.5%
——2Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: Medium)9dCVE-2025-38137—5.5%
——2——CVE-2022-50485—5.5%
——2——CVE-2022-26579—5.5%
——2——CVE-2025-31852—5.5%
——2——CVE-2021-22452—5.5%
——2——CVE-2025-556645.5 MED5.5%
——2A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.10dCVE-2022-43841—5.5%
——2——CVE-2026-96466.1 MED5.5%
——2A reflected cross-site scripting issue exists in URL handling.11dCVE-2025-39425—5.5%
——2——CVE-2026-84244.3 MED5.5%
——2The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'rybb_api_settings' page. This makes it possible for unauthenticated attackers to reset the plugin's stored settings by overwriting its configuration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.9dCVE-2022-22478—5.5%
——2——CVE-2024-57893—5.5%
——2——CVE-2025-28940—5.5%
——2——CVE-2021-22437—5.5%
——2——CVE-2025-381337.8 HIG5.5%
——2In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ad4851: fix ad4858 chan pointer handling
The pointer returned from ad4851_parse_channels_common() is incremented
internally as each channel is populated. In ad4858_parse_channels(),
the same pointer was further incremented while setting ext_scan_type
fields for each channel. This resulted in indio_dev->channels being set
to a pointer past the end of the allocated array, potentially causing
memory corruption or undefined behavior.
Fix this by iterating over the channels using an explicit index instead
of incrementing the pointer. This preserves the original base pointer
and ensures all channel metadata is set correctly.2dCVE-2026-133734.8 MED5.5%
——2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13936.
This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.23dCVE-2026-30007—5.5%
——2——CVE-2023-30904—5.5%
——2——CVE-2025-28941—5.5%
——2——CVE-2026-30006—5.5%
——2——