Vulnerabilities exploitable today
352,785in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,880
- Medium7,174
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-42931—3.5%
——1——CVE-2020-0285—3.5%
——1——CVE-2025-38243—3.5%
——1——CVE-2025-7686—3.5%
——1——CVE-2024-23351—3.5%
——1——CVE-2025-53219—3.5%
——1——CVE-2025-31079—3.5%
——1——CVE-2026-424516.3 MED3.5%
——1Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in Grimmory's browser-based EPUB reader allows an attacker to embed arbitrary JavaScript in a crafted EPUB file. When a victim opens the book, the script executes in their browser with full access to the Grimmory application's session context. This can enable session token theft and account takeover, including administrative access if an administrator opens the affected book. This issue has been patched in version 2.3.1.2dCVE-2026-35641—3.5%
——1——CVE-2026-8010—3.5%
——1——CVE-2023-40074—3.5%
——1——CVE-2025-53263—3.5%
——1——CVE-2025-68712—3.5%
——1——CVE-2023-53029—3.5%
——1——CVE-2025-53262—3.5%
——1——CVE-2025-39781—3.5%
——1——CVE-2025-49239—3.5%
——1——CVE-2023-53022—3.5%
——1——CVE-2026-12003—3.5%
——1——CVE-2026-44995—3.5%
——1——CVE-2023-53412—3.5%
——1——CVE-2024-42300—3.5%
——1——CVE-2025-49446—3.5%
——1——CVE-2023-38418—3.5%
——1——CVE-2025-22637—3.5%
——1——CVE-2025-31410—3.5%
——1——CVE-2026-482727.8 HIG3.5%
——1Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.10dCVE-2019-2117—3.5%
——1——CVE-2020-0284—3.5%
——1——CVE-2025-13684—3.5%
——1——CVE-2024-45067—3.5%
——1——CVE-2025-39888—3.5%
——1——CVE-2022-1739—3.5%
——1——CVE-2025-30986—3.5%
——1——CVE-2026-4530—3.5%
——1——CVE-2026-35368—3.5%
——1——CVE-2025-13144—3.5%
——1——CVE-2026-29089—3.5%
——1——CVE-2026-71865.4 MED3.5%
——1Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a dangerous URI scheme such as javascript: that executes scripts in other users' browsers when they view the dashboard.4dCVE-2023-53441—3.5%
——1——