Vulnerabilities exploitable today
379,234in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,395
- High8,625
- Medium7,065
- Low796
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-47813—34.7%
——10——CVE-2023-38089—34.7%
——10——CVE-2024-24975—34.7%
——10——CVE-2024-52789—34.7%
——10——CVE-2024-47414—34.7%
——10——CVE-2023-34286—34.7%
——10——CVE-2018-10975—34.7%
——10——CVE-2018-10952—34.7%
——10——CVE-2026-917098.8 HIG34.7%
——10Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)7dCVE-2020-8488—34.7%
——10——CVE-2026-25957—34.7%
——10——CVE-2025-57176—34.7%
——10——CVE-2018-3270—34.7%
——10——CVE-2025-30266—34.7%
——10——CVE-2026-8759—34.7%
——10——CVE-2026-84376—34.7%
——10Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check without verifying a path-segment boundary. With base "/app", a request to "/appX/admin" resolved internally to the protected "/admin" route while middleware observed "/appX/admin" in context.url.pathname. In applications that authorize base-prefixed routes by inspecting context.url.pathname, an unauthenticated remote attacker could bypass pathname-based middleware authorization and reach protected routes. This issue is fixed in version 7.2.4.20dCVE-2024-37990—34.7%
——10——CVE-2024-37006—34.7%
——10——CVE-2023-23754—34.7%
——10——CVE-2026-792098.8 HIG34.7%
——10Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)28dCVE-2024-47415—34.7%
——10——CVE-2026-2171—34.7%
——10——CVE-2021-41034—34.7%
——10——CVE-2026-824727.5 HIG34.7%
——10Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.6dCVE-2020-7459—34.7%
——10——CVE-2018-10977—34.7%
——10——CVE-2002-1796—34.7%
——10——CVE-2024-1686—34.7%
——10——CVE-2025-31081—34.7%
——10——CVE-2026-5144—34.7%
——10——CVE-2023-49183—34.7%
——10——CVE-2026-33096.5 MED34.7%
——10The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing user-supplied billing field values from the checkout process to be interpolated into shortcode template strings that are subsequently processed without proper sanitization of shortcode syntax. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes by submitting crafted billing field values during the checkout process.61dCVE-2023-31144—34.7%
——10——CVE-2018-10796—34.7%
——10——CVE-2023-2629—34.7%
——10——CVE-2025-9747—34.7%
——10——CVE-2020-24857—34.7%
——10——CVE-2023-42037—34.7%
——10——CVE-2025-25204—34.7%
——10——CVE-2025-54147—34.7%
——10——