Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-33431—33.1%
——10——CVE-2023-4424—33.1%
——10——CVE-2025-52886—33.1%
——10——CVE-2020-36865—33.1%
——10——CVE-2026-890637.5 HIG33.1%
——10The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the full AI booking conversation transcript of any customer — leaking names, email addresses, phone numbers, and appointment details echoed by the assistant — and inject arbitrary messages into any victim conversation that are subsequently replayed to the Cloud AI worker along with the full private history. Because AI conversations are stored with no owner, user, or session identifier and conversation IDs are sequential integers, an unauthenticated attacker can enumerate all customer conversations simply by incrementing the conversation_id parameter.6dCVE-2026-78570—33.1%
——10Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.21dCVE-2025-57330—33.1%
——10——CVE-2021-47690—33.1%
——10——CVE-2024-12300—33.1%
——10——CVE-2007-6712—33.1%
——10——CVE-2025-21262—33.1%
——10——CVE-2016-15051—33.1%
——10——CVE-2004-0107—33.1%
——10——CVE-2016-10123—33.1%
——10——CVE-2016-1880—33.1%
——10——CVE-2009-0477—33.1%
——10——CVE-2022-43952—33.1%
——10——CVE-2020-36866—33.1%
——10——CVE-2011-0725—33.1%
——10——CVE-2005-1879—33.1%
——10——CVE-2025-7123—33.1%
——10——CVE-2017-3166—33.1%
——10——CVE-2026-44373—33.1%
——10——CVE-2016-10117—33.1%
——10——CVE-2015-8709—33.1%
——10——CVE-2026-23364—33.1%
——10——CVE-2020-36861—33.1%
——10——CVE-2018-19072—33.1%
——10——CVE-2025-46178—33.1%
——10——CVE-2004-1340—33.1%
——10——CVE-2025-11282—33.1%
——10——CVE-2023-5417—33.1%
——10——CVE-2026-751254.9 MED33.1%
——10PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker can send a crafted request omitting the rmtIP parameter to cause the CGI process to dereference a null pointer and crash, resulting in denial of service of the web management interface.14dCVE-2000-0633—33.1%
——10——CVE-2023-5419—33.1%
——10——CVE-2004-0075—33.1%
——10——CVE-2024-28550—33.1%
——10——CVE-2011-10039—33.1%
——10——CVE-2026-653144.3 MED33.1%
——10Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions match rows to deduce sensitive field data even though those columns are not returned in shape responses, bypassing column-based access restrictions.61dCVE-2016-10122—33.1%
——10——