Vulnerabilities exploitable today
352,788in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,882
- Medium7,175
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-10475—3.6%
——1——CVE-2026-348166.4 MED3.6%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.2dCVE-2025-13844—3.6%
——1——CVE-2025-40090—3.6%
——1——CVE-2025-37746—3.6%
——1——CVE-2026-348186.4 MED3.6%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.2dCVE-2025-39882—3.6%
——1——CVE-2026-348096.4 MED3.6%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zonefw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.2dCVE-2026-20602—3.6%
——1——CVE-2026-28573—3.6%
——1——CVE-2019-9351—3.6%
——1——CVE-2026-485345.4 MED3.6%
——1GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by ImapServerWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the IMAP Server configuration page.3dCVE-2022-31635—3.6%
——1——CVE-2022-31638—3.6%
——1——CVE-2026-485375.4 MED3.6%
——1GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded extensions parameter to /Archiver/FileArchiveAssistantWizard.aspx. The injected payload is stored by FileArchiveAssistantWizard.btnSave_Click() without output encoding and is executed in the browsers of users who subsequently view the File Archive Assistant settings page.3dCVE-2026-485395.4 MED3.6%
——1GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by ReportScheduling.btnSaveReport_Click() without output encoding and is executed in the browser of the user who created the scheduled report when they subsequently view the MailInsights page.3dCVE-2026-34676—3.6%
——1——CVE-2022-31637—3.6%
——1——CVE-2022-31636—3.6%
——1——CVE-2020-35548—3.6%
——1——CVE-2026-348146.4 MED3.6%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.2dCVE-2026-242596.4 MED3.6%
——1NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.11dCVE-2026-31153—3.6%
——1——CVE-2026-442285.4 MED3.6%
——1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An authenticated user with permission to set the relevant data can inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.4dCVE-2026-46079—3.6%
——1——CVE-2025-39801—3.6%
——1——CVE-2022-31639—3.6%
——1——CVE-2024-49389—3.6%
——1——CVE-2026-29510—3.6%
——1——CVE-2023-53572—3.6%
——1——CVE-2026-6357—3.6%
——1——CVE-2026-37525—3.6%
——1——CVE-2026-347097.8 HIG3.6%
——1Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2026-28978—3.6%
——1——CVE-2026-90603.5 LOW3.6%
——1The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network where the super admin visits the page).4dCVE-2026-348206.4 MED3.6%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.2dCVE-2022-27538—3.6%
——1——CVE-2026-35054—3.6%
——1——CVE-2025-25011—3.6%
——1——CVE-2025-57624—3.6%
——1——