Vulnerabilities exploitable today
354,348in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,603
- High9,354
- Medium7,537
- Low681
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-12829—4.4%
——1——CVE-2025-60865—4.4%
——1——CVE-2026-579974.8 MED4.4%
——1Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing the jwtSecret can mint tokens with non-standard HMAC variants to bypass algorithm restrictions and weaken authentication controls.29dCVE-2022-40971—4.4%
——1——CVE-2023-53428—4.4%
——1——CVE-2025-20623—4.4%
——1——CVE-2020-27030—4.4%
——1——CVE-2023-27382—4.4%
——1——CVE-2025-30631—4.4%
——1——CVE-2021-0553—4.4%
——1——CVE-2024-42036—4.4%
——1——CVE-2022-50409—4.4%
——1——CVE-2025-52556—4.4%
——1——CVE-2026-606398.8 HIG4.4%
——1Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).1dCVE-2026-489516.1 MED4.4%
——1Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.21dCVE-2023-40375—4.4%
——1——CVE-2025-21018—4.4%
——1——CVE-2022-50314—4.4%
——1——CVE-2023-53234—4.4%
——1——CVE-2023-53546—4.4%
——1——CVE-2026-35253—4.4%
——1——CVE-2022-50395—4.4%
——1——CVE-2026-489496.1 MED4.4%
——1Lack of validation leads to an XSS vulnerability in the MFA management views.21dCVE-2026-489506.1 MED4.4%
——1Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.21dCVE-2023-53479—4.4%
——1——CVE-2022-50511—4.4%
——1——CVE-2020-37234—4.4%
——1——CVE-2023-21361—4.4%
——1——CVE-2022-50535—4.4%
——1——CVE-2022-50334—4.4%
——1——CVE-2025-38444—4.4%
——1——CVE-2022-50299—4.4%
——1——CVE-2022-50421—4.4%
——1——CVE-2025-65965—4.4%
——1——CVE-2022-48989—4.4%
——1——CVE-2026-606368.8 HIG4.4%
——1Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).1dCVE-2025-54033—4.4%
——1——CVE-2025-68702—4.4%
——1——CVE-2022-50531—4.4%
——1——CVE-2023-53589—4.4%
——1——