Vulnerabilities exploitable today
354,449in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,641
- High9,461
- Medium7,688
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-34683—4.6%
——1——CVE-2022-50414—4.6%
——1——CVE-2024-37132—4.6%
——1——CVE-2026-83086.1 MED4.6%
——1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS.
This issue affects Website Template: before v2.6dCVE-2022-50501—4.6%
——1——CVE-2022-50440—4.6%
——1——CVE-2025-24843—4.6%
——1——CVE-2024-45356—4.6%
——1——CVE-2026-658826.1 MED4.6%
——1Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector.2dCVE-2025-64641—4.6%
——1——CVE-2026-28919—4.6%
——1——CVE-2025-12070—4.6%
——1——CVE-2025-397029.8 CRI4.6%
——1In the Linux kernel, the following vulnerability has been resolved:
ipv6: sr: Fix MAC comparison to be constant-time
To prevent timing attacks, MACs need to be compared in constant time.
Use the appropriate helper function for this.21hCVE-2026-90666.1 MED4.6%
——1The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.8dCVE-2025-12776—4.6%
——1——CVE-2022-50484—4.6%
——1——CVE-2026-33883—4.6%
——1——CVE-2026-163987.5 HIG4.6%
——1Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.6dCVE-2026-38669—4.6%
——1——CVE-2023-53489—4.5%
——1——CVE-2026-41395—4.6%
——1——CVE-2022-50251—4.6%
——1——CVE-2025-9632—4.6%
——1——CVE-2026-163997.5 HIG4.6%
——1Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.6dCVE-2022-50344—4.6%
——1——CVE-2025-20198—4.6%
——1——CVE-2022-50244—4.6%
——1——CVE-2022-50312—4.6%
——1——CVE-2022-50289—4.6%
——1——CVE-2026-128696.1 MED4.6%
——1The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import action (it allows any edit_posts user), so a Contributor can import a template containing an Elementor HTML widget configured to display site-wide, injecting JavaScript that executes in the session of any visitor or administrator who loads the site.15dCVE-2022-50430—4.6%
——1——CVE-2022-50242—4.6%
——1——CVE-2025-36173—4.6%
——1——CVE-2022-50309—4.6%
——1——CVE-2022-50462—4.6%
——1——CVE-2022-50324—4.6%
——1——CVE-2026-657566.1 MED4.6%
——1Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.7dCVE-2021-46927—4.5%
——1——CVE-2026-510816.1 MED4.6%
——1A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.13dCVE-2023-53226—4.6%
——1——