Vulnerabilities exploitable today
354,449in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,641
- High9,461
- Medium7,688
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-38636—4.6%
——1——CVE-2026-545457.1 HIG4.6%
——1wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once before writing extracted modules, so a crafted filename containing overlapping traversal sequences such as ....// collapses to ../ after sanitization and lets the final output path escape the selected output directory, allowing an attacker who can cause a user to run wakaru --unpack on a malicious bundle to write files outside that directory and, depending on the target path and environment, potentially achieve code execution. This issue is fixed in @wakaru/cli 1.4.0.9hCVE-2025-13990—4.6%
——1——CVE-2026-28073—4.6%
——1——CVE-2026-48065—4.6%
——1——CVE-2023-53484—4.6%
——1——CVE-2025-47566—4.6%
——1——CVE-2025-1885—4.6%
——1——CVE-2025-54650—4.6%
——1——CVE-2020-0269—4.6%
——1——CVE-2023-32112—4.6%
——1——CVE-2023-53307—4.6%
——1——CVE-2023-53238—4.6%
——1——CVE-2026-21011—4.6%
——1——CVE-2026-537633.8 LOW4.6%
——1OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.0.0 and prior to version 4.11.0, 32-bit integer overflows in OP-TEE core's AES-GCM implementation cause the authentication tag to be computed with incorrect bit-length values after processing more than 512 megabytes of payload or Additional Authenticated Data (AAD). Version 4.11.0 contains a patch. No known workarounds are available.23dCVE-2020-0124—4.6%
——1——CVE-2022-45455—4.6%
——1——CVE-2025-43483—4.6%
——1——CVE-2020-0297—4.6%
——1——CVE-2025-48508—4.6%
——1——CVE-2025-27132—4.6%
——1——CVE-2022-50501—4.6%
——1——CVE-2026-45560—4.6%
——1——CVE-2024-27200—4.6%
——1——CVE-2026-134006.1 MED4.6%
——1Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time.3dCVE-2026-24456.1 MED4.6%
——1The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads.
An attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag.8dCVE-2026-49294—4.6%
——1——CVE-2025-20199—4.6%
——1——CVE-2026-0946—4.6%
——1——CVE-2026-10857—4.6%
——1——CVE-2026-2736—4.6%
——1——CVE-2025-2312—4.6%
——1——CVE-2023-21463—4.6%
——1——CVE-2025-55155—4.5%
——1——CVE-2022-50463—4.6%
——1——CVE-2022-30260—4.6%
——1——CVE-2023-53185—4.6%
——1——CVE-2022-50538—4.6%
——1——CVE-2026-624894.2 MED4.6%
——1Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).3dCVE-2022-20280—4.6%
——1——