Vulnerabilities exploitable today
352,788in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,882
- Medium7,175
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-442295.4 MED3.6%
——1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.4dCVE-2025-70936—3.6%
——1——CVE-2025-37746—3.6%
——1——CVE-2025-32004—3.6%
——1——CVE-2026-348186.4 MED3.6%
——1Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.2dCVE-2025-40090—3.6%
——1——CVE-2026-115695.4 MED3.6%
——1A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. The file is stored and served inline through the CDN, enabling stored cross-site scripting when a victim visits the archive URL.4dCVE-2026-35054—3.6%
——1——CVE-2026-485385.4 MED3.6%
——1GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured folders parameter to /Archiver/ImportSettingsWizard.ashx. The injected payload is stored by ImportSettingsWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Archive Assistant default import settings.3dCVE-2025-54413—3.6%
——1——CVE-2025-66843—3.6%
——1——CVE-2017-14900—3.6%
——1——CVE-2026-9618—3.6%
——1——CVE-2026-43260—3.6%
——1——CVE-2025-38233—3.6%
——1——CVE-2026-1553—3.6%
——1——CVE-2023-53579—3.6%
——1——CVE-2019-256585.5 MED3.6%
——1a-Mac Address Change 5.4 contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input to registration form fields. Attackers can paste 212 bytes of data into the 'Your Name', 'Your Company', or 'Register Code' fields and click the Register button to trigger a denial of service crash.2dCVE-2025-63060—3.6%
——1——CVE-2026-126895.4 MED3.6%
——1The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.2dCVE-2017-0865—3.6%
——1——CVE-2017-17138—3.6%
——1——CVE-2025-38641—3.6%
——1——CVE-2025-2272—3.6%
——1——CVE-2017-11027—3.6%
——1——CVE-2025-38228—3.6%
——1——CVE-2026-132384.8 MED3.6%
——1Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.13dCVE-2026-3341—3.6%
——1——CVE-2017-13161—3.6%
——1——CVE-2024-47122—3.6%
——1——CVE-2025-39792—3.6%
——1——CVE-2026-529528.8 HIG3.6%
——1In the Linux kernel, the following vulnerability has been resolved:
iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset
In __iommu_group_set_domain_internal(), concurrent domain attachments are
rejected when any device in the group is recovering. This is necessary to
fence concurrent attachments to a multi-device group where devices might
share the same RID due to PCI DMA alias quirks, but triggers the WARN_ON in
__iommu_group_set_domain_nofail().
Other IOMMU_SET_DOMAIN_MUST_SUCCEED callers in detach/teardown paths, such
as __iommu_group_set_core_domain and __iommu_release_dma_ownership, should
not be rejected, as the domain would be freed anyway in these nofail paths
while group->domain is still pointing to it. So pci_dev_reset_iommu_done()
could trigger a UAF when re-attaching group->domain.
Honor the IOMMU_SET_DOMAIN_MUST_SUCCEED flag, allowing the callers through
the group->recovery_cnt fence, so as to update the group->domain pointer.
Instead add a gdev->blocked check in the device iteration loop, to prevent
any concurrent per-device detachment.12dCVE-2026-13507—3.6%
——1——CVE-2021-39078—3.6%
——1——CVE-2017-11016—3.6%
——1——CVE-2022-29839—3.6%
——1——CVE-2017-14901—3.6%
——1——CVE-2024-20854—3.6%
——1——CVE-2025-0990—3.6%
——1——CVE-2017-11073—3.6%
——1——