Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-49694—31.4%
——9——CVE-2015-5448—31.4%
——9——CVE-2013-6049—31.4%
——9——CVE-2025-68111—31.4%
——9——CVE-2024-2731—31.4%
——9——CVE-2014-6147—31.4%
——9——CVE-2013-2007—31.4%
——9——CVE-2026-96266.4 MED31.4%
——9The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and including, 4.1.0 This is due to insufficient input sanitization in the post_comment() function, which passes the attacker-controlled comment_content value directly to wp_insert_comment() without applying any HTML sanitization, and additionally allows the caller to set comment_approved=1 to self-approve the comment and bypass moderation. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.77dCVE-2026-449268.8 HIG31.4%
——9InfoScale CmdServer before 7.4.2 mishandles access control.60dCVE-2016-3640—31.4%
——9——CVE-2025-29156—31.4%
——9——CVE-2017-6718—31.4%
——9——CVE-2021-1118—31.4%
——9——CVE-2026-45311—31.4%
——9——CVE-2024-25224—31.4%
——9——CVE-2026-43139—31.4%
——9——CVE-2026-828157.3 HIG31.4%
——9A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.19dCVE-2025-5184—31.4%
——9——CVE-2026-535918.6 HIG31.4%
——9FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted `In-Reply-To` header. No credentials, tokens, or prior access are required. The injected message is rendered in the agent UI as a legitimate customer reply, the conversation is automatically reopened, and the `last_reply_from` field is set to the attacker's identity. Version 1.8.223 contains a fix.61dCVE-2026-452889.8 CRI31.4%
——9Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to untrusted input a SQL injection sink. This vulnerability is fixed in 8.36.1.62dCVE-2020-10659—31.4%
——9——CVE-2024-29469—31.4%
——9——CVE-2002-0849—31.4%
——9——CVE-2023-21479—31.4%
——9——CVE-2026-843735.9 MED31.4%
——9Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the vitest:interceptor:register handler on Vite's unauthenticated HMR WebSocket without validating redirect targets against the file-serving allowlist. The implementation processes event.redirect without enforcing server.fs.allow and server.fs.deny through isFileLoadingAllowed. A remote client that can reach an exposed development server can submit an opaque URL scheme preserving .. segments, causing join(server.config.root, redirectUrl.pathname) to resolve outside the project root. The plugin's load hook then returns readFile(mock.redirect, 'utf-8') as module source, disclosing local files readable by the dev-server process. Vitest browser mode uses a token-authenticated RPC and is not remotely unauthenticated by default, although the same boundary check was missing on that path. This issue is fixed in versions 4.1.11 and 5.0.0-rc.2.19dCVE-2024-25597—31.4%
——9——CVE-2025-49693—31.4%
——9——CVE-2025-10743—31.4%
——9——CVE-2004-1263—31.4%
——9——CVE-2026-39007—31.4%
——9——CVE-2026-193007.5 HIG31.4%
——9IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.12dCVE-2024-34071—31.4%
——9——CVE-2020-10277—31.4%
——9——CVE-2026-829577.3 HIG31.4%
——9A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.19dCVE-2026-750154.9 MED31.4%
——9Insufficiently Protected Credentials vulnerability in Apache Syncope.
Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.6dCVE-2022-34260—31.4%
——9——CVE-2021-25671—31.4%
——9——CVE-2023-0010—31.4%
——9——CVE-2026-492227.6 HIG31.4%
——9Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product question operations allow a low-privileged Vendor to manage questions under another Vendor's products. The admin/sql/sqlite/product_question.sql queries accept a caller-controlled product_question_id and do not verify product_question.product_id against product.admin_id for the current admin_id. An attacker can read pending question content and moderation data, change question status, edit question content, or delete questions, manipulating product Q&A visibility and integrity. This issue is fixed in version 1.0.8.4.12dCVE-2023-42533—31.4%
——9——