Vulnerabilities exploitable today
352,969in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,334
- High8,050
- Medium7,230
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-21362—3.9%
——1——CVE-2026-361625.4 MED3.9%
——1An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.18dCVE-2025-13984—3.9%
——1——CVE-2026-53655—3.9%
——1——CVE-2025-26577—3.9%
——1——CVE-2026-619016.1 MED3.9%
——1Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.4dCVE-2022-38684—3.9%
——1——CVE-2026-32866—3.9%
——1——CVE-2026-23757—3.9%
——1——CVE-2023-40083—3.9%
——1——CVE-2022-38678—3.9%
——1——CVE-2025-13606—3.9%
——1——CVE-2026-32868—3.9%
——1——CVE-2026-32869—3.9%
——1——CVE-2026-82846.1 MED3.9%
——1URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation.
This issue affects FlexCity: from 5.536.0 through 11052026.6dCVE-2020-10839—3.9%
——1——CVE-2026-483057.8 HIG3.9%
——1Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2026-35634—3.9%
——1——CVE-2026-23756—3.9%
——1——CVE-2025-11697—3.9%
——1——CVE-2026-22482—3.9%
——1——CVE-2026-483067.8 HIG3.9%
——1Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2026-99913.1 LOW3.9%
——1Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)6dCVE-2025-26759—3.9%
——1——CVE-2026-348485.4 MED3.9%
——1hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow tooltip via display name. This issue has been patched in version 2026.3.0.3dCVE-2025-43393—3.9%
——1——CVE-2025-38170—3.9%
——1——CVE-2026-40729—3.9%
——1——CVE-2024-56493—3.9%
——1——CVE-2024-56494—3.9%
——1——CVE-2026-40786—3.9%
——1——CVE-2025-13634—3.9%
——1——CVE-2024-43862—3.9%
——1——CVE-2024-42184—3.9%
——1——CVE-2020-0483—3.9%
——1——CVE-2026-4377—3.9%
——1——CVE-2023-41822—3.9%
——1——CVE-2026-537415.4 MED3.9%
——1Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.4dCVE-2025-26580—3.9%
——1——CVE-2025-26550—3.9%
——1——