Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-54329—32.4%
——10——CVE-2026-729804.4 MED32.4%
——10Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.4dCVE-2023-42547—32.4%
——10——CVE-2024-6286—32.4%
——10——CVE-2023-1981—32.4%
——10——CVE-2024-34590—32.4%
——10——CVE-2019-18897—32.4%
——10——CVE-2023-40271—32.4%
——10——CVE-2023-1732—32.4%
——10——CVE-2021-24618—32.4%
——10——CVE-2006-1506—32.4%
——10——CVE-2026-825388.8 HIG32.4%
——10ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover.7dCVE-1999-1197—32.4%
——10——CVE-2004-0831—32.4%
——10——CVE-2025-503278.8 HIG32.4%
——10An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism59dCVE-2020-4005—32.4%
——10——CVE-2024-48783—32.4%
——10——CVE-2015-0665—32.4%
——10——CVE-1999-1396—32.4%
——10——CVE-2023-42551—32.4%
——10——CVE-2024-51257—32.4%
——10——CVE-2024-28823—32.4%
——10——CVE-2023-38826—32.4%
——10——CVE-2023-21949—32.4%
——10——CVE-2024-13403—32.4%
——10——CVE-2014-1929—32.4%
——10——CVE-2016-5242—32.4%
——10——CVE-2023-47543—32.4%
——10——CVE-2022-41919—32.4%
——10——CVE-2025-51534—32.4%
——10——CVE-2026-125604.4 MED32.4%
——10The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Link URL' Field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The WordPress unfiltered_html capability exemption does not apply here because the payload is stored in post meta (_wpas_er_options via update_post_meta) rather than in post_content or post_excerpt, meaning the restriction affects all administrators regardless of their unfiltered_html status.82dCVE-2018-20944—32.4%
——10——CVE-1999-1252—32.4%
——10——CVE-2024-1272—32.4%
——10——CVE-2024-20789—32.4%
——10——CVE-1999-1253—32.4%
——10——CVE-2024-50615—32.4%
——10——CVE-2013-2096—32.4%
——10——CVE-2018-20939—32.4%
——10——CVE-2014-2894—32.4%
——10——