Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-21924—32.6%
——10——CVE-2026-131164.3 MED32.6%
——10The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to mint publicly accessible, session-free download links for arbitrary third-party orders, exposing customer names, billing and shipping addresses, email addresses, phone numbers, order and invoice numbers, line items, totals, payment details, and customer notes contained in those orders' invoices and packing slips. Exploitation requires the plugin's Document link access type setting to be configured to 'full'; with the default 'logged_in' value, generated URLs are signed with a per-session nonce rather than the order_key, making the shortcode path unexploitable for unauthorized access to third-party orders.70dCVE-2024-26236—32.6%
——10——CVE-2026-27906—32.6%
——10——CVE-2019-2940—32.6%
——10——CVE-2024-26243—32.6%
——10——CVE-2026-627035.5 MED32.6%
——10Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.36dCVE-2026-572145.4 MED32.6%
——10RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.70dCVE-2024-3208—32.6%
——10——CVE-2025-20336—32.6%
——10——CVE-2026-5971—32.6%
——10——CVE-2012-6120—32.6%
——10——CVE-2026-695685.5 MED32.6%
——10Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.3dCVE-2024-11278—32.6%
——10——CVE-2026-760448.3 HIG32.6%
——10Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)31dCVE-2000-0069—32.6%
——10——CVE-2024-13529—32.6%
——10——CVE-2026-195608.8 HIG32.6%
——10Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)35dCVE-2023-24400—32.6%
——10——CVE-2026-570749.1 CRI32.6%
——10XML::Bare versions through 0.53 for Perl have an unbounded character lookahead.
The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer.
Truncated strings such as "<a/" can trigger an out-of-bounds read.66dCVE-2014-1353—32.6%
——10——CVE-2025-48783—32.6%
——10——CVE-2024-5715—32.6%
——10——CVE-2026-121134.3 MED32.6%
——10The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email addresses, phone numbers, appointment comments, and other booking personally identifiable information.82dCVE-2022-45215—32.6%
——10——CVE-2024-35292—32.6%
——10——CVE-2026-41333—32.6%
——10——CVE-2026-30887—32.6%
——10——CVE-2022-4956—32.6%
——10——CVE-2026-0776—32.6%
——10——CVE-2023-25893—32.6%
——10——CVE-2025-0614—32.6%
——10——CVE-2021-46666—32.6%
——10——CVE-2026-347857.5 HIG32.6%
——10Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.59dCVE-2026-28954—32.6%
——10——CVE-2017-9780—32.6%
——10——CVE-2025-0615—32.6%
——10——CVE-2014-1351—32.6%
——10——CVE-2025-41710—32.6%
——10——CVE-2025-10389—32.6%
——10——