Vulnerabilities exploitable today
354,689in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,617
- High9,375
- Medium7,592
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-50076—5.3%
——2——CVE-2022-20482—5.3%
——2——CVE-2023-45240—5.3%
——2——CVE-2022-50075—5.3%
——2——CVE-2026-391796.3 MED5.3%
——2A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.23dCVE-2024-21953—5.3%
——2——CVE-2022-50049—5.3%
——2——CVE-2026-346245.4 MED5.3%
——2Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage.7dCVE-2024-36324—5.3%
——2——CVE-2026-346255.4 MED5.3%
——2Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage.7dCVE-2022-20511—5.3%
——2——CVE-2021-30303—5.3%
——2——CVE-2024-13057—5.3%
——2——CVE-2023-30711—5.3%
——2——CVE-2019-9257—5.3%
——2——CVE-2025-38531—5.3%
——2——CVE-2019-9469—5.3%
——2——CVE-2022-32643—5.3%
——2——CVE-2025-38628—5.3%
——2——CVE-2019-9258—5.3%
——2——CVE-2026-3202—5.3%
——2——CVE-2025-61861—5.3%
——2——CVE-2025-24840—5.3%
——2——CVE-2025-64893—5.3%
——2——CVE-2022-22058—5.3%
——2——CVE-2024-52424—5.3%
——2——CVE-2025-61862—5.3%
——2——CVE-2020-27046—5.3%
——2——CVE-2020-36985—5.3%
——2——CVE-2025-50044—5.3%
——2——CVE-2019-25292—5.3%
——2——CVE-2026-396945.3 MED5.3%
——2Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.10.2.8dCVE-2025-38426—5.3%
——2——CVE-2025-43913—5.3%
——2——CVE-2024-32488—5.3%
——2——CVE-2026-396985.3 MED5.3%
——2Missing Authorization vulnerability in PublisherDesk The Publisher Desk ads.txt the-publisher-desk-ads-txt allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Publisher Desk ads.txt: from n/a through <= 1.5.0.8dCVE-2026-6712—5.3%
——2——CVE-2026-35096—5.3%
——2KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged POST request to the application. This allows the attacker to trigger an unauthorized email or password change on behalf of the victim without their knowledge or interaction.
This issue was fixed in the patch published in June 2026.32dCVE-2025-13835—5.3%
——2——CVE-2026-41376—5.3%
——2——