Vulnerabilities exploitable today
353,604in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,655
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,451
- High8,318
- Medium7,448
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-7008—4.3%
——1——CVE-2025-53649—4.3%
——1——CVE-2026-56813—4.3%
——1——CVE-2020-3483—4.3%
——1——CVE-2026-24071—4.3%
——1——CVE-2025-3892—4.3%
——1——CVE-2021-26381—4.3%
——1——CVE-2025-7004—4.3%
——1——CVE-2019-9295—4.3%
——1——CVE-2025-38303—4.3%
——1——CVE-2026-32529—4.3%
——1——CVE-2026-8370—4.3%
——1Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64, Solaris Sparc 64 allows Privilege Escalation, Target Programs with Elevated Privileges.
This issue affects Automic Automation: < 24.4.4 HF1.6dCVE-2026-32542—4.3%
——1——CVE-2026-32540—4.3%
——1——CVE-2026-45920—4.3%
——1——CVE-2025-30965—4.3%
——1——CVE-2026-9570—4.3%
——1——CVE-2025-15523—4.3%
——1——CVE-2026-278824.8 MED4.3%
——1Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.461, the GitLab webhook endpoint uses a non-constant-time string comparison operator (!==) to validate the webhook secret token. This implementation is vulnerable to timing attacks, which could allow an attacker to gradually discover the secret token by measuring response time differences. This vulnerability is fixed in 4.0.0-beta.461.29dCVE-2025-38251—4.3%
——1——CVE-2022-20044—4.3%
——1——CVE-2019-14070—4.3%
——1——CVE-2022-31752—4.3%
——1——CVE-2026-1769—4.3%
——1——CVE-2026-28110—4.3%
——1——CVE-2026-32061—4.3%
——1——CVE-2025-20238—4.3%
——1——CVE-2026-35667—4.3%
——1——CVE-2025-156547.1 HIG4.3%
——1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS.
This issue affects Prague: from n/a through 2.2.8.7dCVE-2026-654477.1 HIG4.3%
——1Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.23hCVE-2025-38343—4.3%
——1——CVE-2026-654387.1 HIG4.3%
——1Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.23hCVE-2021-1928—4.3%
——1——CVE-2026-654437.1 HIG4.3%
——1Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.23hCVE-2026-654417.1 HIG4.3%
——1Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.23hCVE-2026-654407.1 HIG4.3%
——1Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.23hCVE-2026-27072—4.3%
——1——CVE-2026-654397.1 HIG4.3%
——1Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.23hCVE-2026-438195.5 MED4.3%
——1An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive user data.20hCVE-2024-27273—4.3%
——1——