Vulnerabilities exploitable today
352,791in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,306
- High8,002
- Medium7,177
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-43150—3.7%
——1——CVE-2026-40734—3.7%
——1——CVE-2025-46507—3.7%
——1——CVE-2025-432895.5 MED3.7%
——1A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to access sensitive user data.4dCVE-2025-46492—3.7%
——1——CVE-2026-46036—3.7%
——1——CVE-2022-40517—3.7%
——1——CVE-2026-43214—3.7%
——1——CVE-2024-47892—3.7%
——1——CVE-2022-48305—3.7%
——1——CVE-2025-30655—3.7%
——1——CVE-2018-25298—3.6%
——1——CVE-2026-46129—3.7%
——1——CVE-2026-46206—3.7%
——1——CVE-2026-348126.4 MED3.6%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the mimetypes parameter to /cgi-bin/proxypolicy.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.2dCVE-2024-49389—3.6%
——1——CVE-2026-455748.1 HIG3.6%
——1epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential exchanges. This vulnerability is fixed in 1.2.2.3dCVE-2026-346317.8 HIG3.6%
——1InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.2dCVE-2022-31639—3.6%
——1——CVE-2026-347097.8 HIG3.6%
——1Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2022-27538—3.6%
——1——CVE-2026-37525—3.6%
——1——CVE-2025-64170—3.6%
——1——CVE-2023-53572—3.6%
——1——CVE-2026-6357—3.6%
——1——CVE-2026-483367.8 HIG3.6%
——1Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.11dCVE-2026-28978—3.6%
——1——CVE-2026-29513—3.6%
——1——CVE-2025-37783—3.6%
——1——CVE-2024-56429—3.6%
——1——CVE-2026-90603.5 LOW3.6%
——1The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network where the super admin visits the page).4dCVE-2026-348206.4 MED3.6%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.2dCVE-2025-4095—3.6%
——1——CVE-2026-348086.4 MED3.6%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.2dCVE-2025-39944—3.6%
——1——CVE-2024-38306—3.6%
——1——CVE-2021-37684—3.6%
——1——CVE-2023-53254—3.6%
——1——CVE-2022-50371—3.6%
——1——CVE-2026-36766—3.6%
——1——