Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,705
- Medium6,988
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-9109—34.1%
——10——CVE-2026-595259.3 CRI34.1%
——10Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.62dCVE-2026-770848.8 HIG34.1%
——10n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reachable through the Git node's own configuration controls and requires a separate file-write vulnerability elsewhere to plant the malicious value.22dCVE-2023-52944—34.1%
——10——CVE-2026-54820—34.1%
——10——CVE-2024-13950—34.1%
——10——CVE-2026-595269.3 CRI34.1%
——10Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.62dCVE-2025-53094—34.1%
——10——CVE-2023-47546—34.1%
——10——CVE-2025-3767—34.1%
——10——CVE-2026-56036—34.1%
——10——CVE-2019-8748—34.1%
——10——CVE-2026-43575—34.1%
——10——CVE-2026-905724.7 MED34.1%
——10A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to memory corruption. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.8dCVE-2024-41849—34.1%
——10——CVE-2021-1815—34.1%
——10——CVE-2018-6147—34.1%
——10——CVE-2022-23502—34.1%
——10——CVE-2026-54825—34.1%
——10——CVE-2026-36888.1 HIG34.1%
——10The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.77dCVE-2024-24424—34.1%
——10——CVE-2023-45829—34.1%
——10——CVE-2026-757839.6 CRI34.1%
——10A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used.34dCVE-2023-70706.4 MED34.1%
——10The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eeb_mailto shortcode in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.63dCVE-2026-56070—34.1%
——10——CVE-2024-2474—34.1%
——10——CVE-2026-759328.6 HIG34.1%
——10Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.33dCVE-2025-41067—34.1%
——10——CVE-2022-46503—34.1%
——10——CVE-2026-51274—34.1%
——10Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.54dCVE-2024-40732—34.1%
——10——CVE-2025-31484—34.1%
——10——CVE-2017-18396—34.1%
——10——CVE-2025-30214—34.1%
——10——CVE-2024-40729—34.1%
——10——CVE-2023-5621—34.1%
——10——CVE-2023-30417—34.1%
——10——CVE-2025-20190—34.1%
——10——CVE-2025-8708—34.1%
——10——CVE-2026-581807.5 HIG34.1%
——10The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.54d