Vulnerabilities exploitable today
378,026in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,410
- Medium6,691
- Low753
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-162264.7 MED31.5%
——9A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.63dCVE-2026-18236—31.5%
——9A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible because the framework did not verify if the target tool was registered to the executing agent, did not validate if the tool actually required confirmation, and did not match the confirmation arguments against the original tool call event in the history.53dCVE-2021-20263—31.5%
——9——CVE-2026-458047.5 HIG31.5%
——9Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub repository with custom .py pipeline code to execute through the custom pipeline flow without passing custom_pipeline or trust_remote_code=True. This issue is fixed in version 0.38.0.40dCVE-2024-25360—31.5%
——9——CVE-2024-37430—31.5%
——9——CVE-2023-1209—31.5%
——9——CVE-2015-3959—31.5%
——9——CVE-2014-4356—31.5%
——9——CVE-2010-3015—31.5%
——9——CVE-2019-3716—31.5%
——9——CVE-2024-33574—31.5%
——9——CVE-2024-33573—31.5%
——9——CVE-2019-16001—31.5%
——9——CVE-2026-318189.6 CRI31.5%
——9Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely ineffective because the BLACKLIST_IPS environment variable is not set by default in any of the official deployment configurations. When this variable is empty, the blacklist function unconditionally returns false, allowing all requests through without restriction. This issue has been patched in version 3.33.4.58dCVE-2022-30361—31.5%
——9——CVE-2017-9450—31.5%
——9——CVE-2018-9566—31.5%
——9——CVE-2017-18861—31.5%
——9——CVE-2009-0480—31.5%
——9——CVE-2026-759614.9 MED31.5%
——9The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The operator allowlist applied by get_table_records() when building its own WHERE fragment is not enforced on the same tainted additional_params array when it is forwarded to get_total_records(), leaving the SQL sink unprotected.2dCVE-2026-155184.7 MED31.5%
——9A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. Such manipulation of the argument qqfilename leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.70dCVE-2013-5691—31.5%
——9——CVE-2023-26965—31.5%
——9——CVE-2013-3400—31.5%
——9——CVE-2026-444509.9 CRI31.5%
——9Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Every binary on the allowlist accepts an inline-code execution flag (-e for node/bun, -c for python3/deno), giving any logged-in user arbitrary OS-level code execution on the Lumiverse server. The route requires only requireAuth (not requireOwner). The server binds on all interfaces (::) and the host-header rebinding check is bypassed trivially by any HTTP client that sends Host: localhost:<port> directly, making this exploitable from any machine with network access to the server port. This vulnerability is fixed in 0.9.7.60dCVE-2024-3587—31.5%
——9——CVE-2026-854528.8 HIG31.5%
——9MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.13dCVE-2024-32037—31.5%
——9——CVE-2022-42402—31.5%
——9——CVE-2024-8158—31.5%
——9——CVE-2014-9191—31.5%
——9——CVE-2024-11583—31.5%
——9——CVE-2023-21978—31.5%
——9——CVE-2023-28900—31.5%
——9——CVE-2024-28297—31.5%
——9——CVE-2025-25875—31.5%
——9——CVE-2023-5514—31.5%
——9——CVE-2018-1448—31.5%
——9——CVE-2026-159187.5 HIG31.5%
——9VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value is placed directly into the query, an attacker who is not logged in can inject arbitrary SQL through a normal booking page and read data from the site's database — including sensitive information such as WordPress user credentials. No authentication or special privileges are required39d