Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-0821—33.7%
——10——CVE-2019-9808—33.7%
——10——CVE-2022-26328—33.7%
——10——CVE-2023-40673—33.7%
——10——CVE-2023-4135—33.7%
——10——CVE-2022-3563—33.7%
——10——CVE-2018-3915—33.7%
——10——CVE-2020-2689—33.7%
——10——CVE-2021-31989—33.7%
——10——CVE-2026-153699.8 CRI33.7%
——10The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in the af_reg_checkout_data_to_order_meta_data_block() function, persisting it in order meta, and then passing it directly to WP_User::add_role() in the af_reg_custom_order_processing_function() function (hooked to woocommerce_thankyou) without validating against the plugin's admin-configured allowed role list. This makes it possible for unauthenticated attackers to elevate their privileges to Administrator by creating an account during checkout with a modified JSON body specifying administrator (or any other role slug) as the desired role. Note: The exploit requires the "User Role Selection" setting to be enabled.22dCVE-2025-5554—33.7%
——10——CVE-2024-3547—33.7%
——10——CVE-2026-72815—33.7%
——10go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. The issue is fixed in version 5.3.0.36dCVE-2021-29837—33.7%
——10——CVE-2024-45689—33.7%
——10——CVE-2026-761339.8 CRI33.7%
——10The affected Ebyte
product
uses a deprecated hashing algorithm in an authentication-related
operation. Under conditions where an attacker can manipulate or predict
the authentication exchange, the weak construction may reduce the
assurance provided by the authentication mechanism and facilitate
unauthorized access.21dCVE-2023-23816—33.7%
——10——CVE-2023-34087—33.7%
——10——CVE-2005-4278—33.7%
——10——CVE-2026-189907.3 HIG33.7%
——10A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.41dCVE-2026-7182—33.7%
——10——CVE-1999-0892—33.7%
——10——CVE-2026-0869—33.7%
——10——CVE-2010-3859—33.7%
——10——CVE-1999-0457—33.7%
——10——CVE-2026-425707.5 HIG33.7%
——10Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption. This issue has been patched in version 5.8.1.29dCVE-2026-31283—33.7%
——10——CVE-2024-27952—33.7%
——10——CVE-2026-442219.0 CRI33.7%
——10ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap, which requestAccessOnFile treated as allow-all; (2) ArcadeDBServer.createDatabase() omitted factory.setSecurity(...) so any database created via POST /api/v1/server {"command":"create database X"} had its entire record-level authorization system silently disabled. In combination, record-level and database-level authorization could be bypassed by any authenticated principal. This vulnerability is fixed in 26.4.2.50dCVE-2026-39951—33.7%
——10——CVE-2026-479958.1 HIG33.7%
——10Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.26dCVE-2026-3483—33.7%
——10——CVE-2021-29757—33.7%
——10——CVE-2017-16996—33.7%
——10——CVE-2026-32367—33.7%
——10——CVE-2022-27851—33.7%
——10——CVE-2025-5784—33.7%
——10——CVE-2018-5073—33.7%
——10——CVE-2025-32808—33.7%
——10——CVE-2022-24448—33.7%
——10——