Vulnerabilities exploitable today
354,756in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,619
- High9,379
- Medium7,621
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-43841—5.5%
——2——CVE-2025-556645.5 MED5.5%
——2A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.10dCVE-2025-31852—5.5%
——2——CVE-2026-96466.1 MED5.5%
——2A reflected cross-site scripting issue exists in URL handling.11dCVE-2021-22452—5.5%
——2——CVE-2022-26579—5.5%
——2——CVE-2022-50485—5.5%
——2——CVE-2026-343597.4 HIG5.5%
——2HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authentication credential dispatch. Because configured server URLs (e.g., http://tx.fhir.org) lack a trailing slash or host boundary check, an attacker-controlled domain like http://tx.fhir.org.attacker.com matches the prefix and receives Bearer tokens, Basic auth credentials, or API keys when the HTTP client follows a redirect to that domain. This issue has been patched in version 6.9.4.8dCVE-2022-22478—5.5%
——2——CVE-2024-57893—5.5%
——2——CVE-2026-28195—5.5%
——2——CVE-2023-30709—5.5%
——2——CVE-2024-12541—5.5%
——2——CVE-2026-133774.8 MED5.5%
——2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-6947.
This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.23dCVE-2021-25390—5.5%
——2——CVE-2021-22326—5.5%
——2——CVE-2025-28910—5.5%
——2——CVE-2026-110486.5 MED5.5%
——2Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: Medium)9dCVE-2025-41104—5.5%
——2——CVE-2025-29999—5.5%
——2——CVE-2025-28909—5.5%
——2——CVE-2025-38137—5.5%
——2——CVE-2025-22297—5.5%
——2——CVE-2026-141893.8 LOW5.5%
——2The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.5dCVE-2024-54005—5.5%
——2——CVE-2025-39453—5.5%
——2——CVE-2020-0043—5.5%
——2——CVE-2025-28902—5.5%
——2——CVE-2025-41101—5.5%
——2——CVE-2025-37953—5.5%
——2——CVE-2024-0833—5.5%
——2——CVE-2024-22386—5.5%
——2——CVE-2025-24540—5.5%
——2——CVE-2025-28887—5.5%
——2——CVE-2022-20453—5.5%
——2——CVE-2026-12445—5.5%
——2——CVE-2024-10074—5.5%
——2——CVE-2024-31118—5.5%
——2——CVE-2025-28940—5.5%
——2——CVE-2025-28941—5.5%
——2——