Vulnerabilities exploitable today
379,234in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,371
- High8,538
- Medium7,064
- Low795
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-2090—34.8%
——10——CVE-2026-585015.9 MED34.8%
——10Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to fetch attacker-chosen HTTP or HTTPS URLs. This issue is fixed in version 4.3.3.76dCVE-2026-83516.4 MED34.8%
——10The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in versions up to, and including, 2.0.7 This is due to insufficient output escaping on the 'background_text_heading' setting in the render() function, which concatenates the value directly into an HTML attribute without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.80dCVE-2026-169077.6 HIG34.8%
——10IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.38dCVE-2026-862617.3 HIG34.8%
——10A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Controller. Executing a manipulation of the argument userIdenf can lead to authorization bypass. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.16dCVE-2026-877474.9 MED34.8%
——10The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files.15dCVE-2024-13084—34.8%
——10——CVE-2024-33953—34.8%
——10——CVE-2024-32721—34.8%
——10——CVE-2025-11253—34.8%
——10——CVE-2022-47601—34.8%
——10——CVE-2023-51298—34.8%
——10——CVE-2006-0674—34.8%
——10——CVE-2021-20468—34.8%
——10——CVE-2025-20058—34.8%
——10——CVE-2020-4301—34.8%
——10——CVE-2017-13295—34.8%
——10——CVE-2023-0817—34.8%
——10——CVE-2024-26490—34.8%
——10——CVE-2025-24326—34.8%
——10——CVE-2026-42435—34.8%
——10——CVE-2021-31155—34.8%
——10——CVE-2025-52984—34.8%
——10——CVE-2026-618026.5 MED34.8%
——10Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration endpoint that fails to redact it. The REST API provides a masking control, mask_sensitive_config, that redacts sensitive fields such as authd.pass and cluster.key from configuration responses for users who lack update-config permission, and every config-read endpoint carries this decorator except GET /cluster/local/config. That endpoint, backed by read_config_wrapper, is gated only by cluster:read and returns the local node's cluster configuration including the cleartext key, whereas its siblings return the same value masked. As a result, any account with the default readonly or cluster_readonly role, which is explicitly denied update-config precisely so it cannot view secrets, receives the real cluster key. Because the cluster key authenticates and encrypts traffic between cluster nodes, disclosing it to an unprivileged account provides the authentication precondition for the cluster-peer remote code execution chains established by prior advisories. This issue is fixed in version 4.14.9dCVE-2026-40360—34.8%
——10——CVE-2026-862637.3 HIG34.8%
——10A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.16dCVE-2025-60339—34.8%
——10——CVE-2025-64718—34.8%
——10——CVE-2025-3698—34.8%
——10——CVE-2024-13197—34.8%
——10——CVE-2024-13192—34.8%
——10——CVE-2024-45979—34.8%
——10——CVE-2026-34839—34.8%
——10——CVE-2026-29613—34.8%
——10——CVE-2020-22273—34.8%
——10——CVE-2024-33584—34.8%
——10——CVE-2025-59362—34.8%
——10——CVE-2025-26468—34.8%
——10——CVE-2026-25228—34.8%
——10——CVE-2025-127996.5 MED34.8%
——10A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.57d