Vulnerabilities exploitable today
363,254in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,888
- High12,346
- Medium7,598
- Low718
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2006-2395—88.5%
——27——CVE-2004-2574—88.5%
——27——CVE-2017-10928—88.5%
——27——CVE-2009-2797—88.4%
——27——CVE-2015-5779—88.5%
——27——CVE-2018-8153—88.5%
——27——CVE-2021-1701—88.5%
——27——CVE-2018-0229—88.4%
——27——CVE-2021-46560—88.5%
——27——CVE-2014-3210—88.5%
——27——CVE-2013-0288—88.5%
——27——CVE-2018-17997—88.5%
——27——CVE-2018-11392—88.5%
——27——CVE-2021-28576—88.5%
——27——CVE-2017-14266—88.5%
——27——CVE-2014-4979—88.5%
——27——CVE-2026-107958.1 HIG88.5%
——27The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.28dCVE-2004-1207—88.5%
——27——CVE-2010-1642—88.5%
——27——CVE-2012-0188—88.5%
——27——CVE-2016-9397—88.5%
——27——CVE-2026-336916.8 MED88.5%
——27The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.27dCVE-2022-1531—88.5%
——27——CVE-2018-17621—88.5%
——27——CVE-2007-4947—88.5%
——27——CVE-2017-9003—88.5%
——27——CVE-2022-442909.8 CRI88.5%
——27webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.43dCVE-2017-5400—88.5%
——27——CVE-2018-0683—88.5%
——27——CVE-2021-23338—88.5%
——27——CVE-2012-3435—88.5%
——27——CVE-2008-3538—88.4%
——27——CVE-2022-30708—88.5%
——27——CVE-2001-0217—88.5%
——27——CVE-2021-345248.1 HIG88.5%
——27Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability10dCVE-2019-8250—88.5%
——27——CVE-2021-413514.3 MED88.5%
——27Microsoft Edge (Chrome based) Spoofing on IE Mode1dCVE-2005-1228—88.5%
——27——CVE-2015-7907—88.5%
——27——CVE-2019-1971—88.5%
——27——