Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,321
- High8,305
- Medium6,571
- Low708
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-20178—30.2%
——9——CVE-2025-7948—30.2%
——9——CVE-2026-2159—30.2%
——9——CVE-2025-37137—30.2%
——9——CVE-2026-890276.5 MED30.2%
——9miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.3dCVE-2026-40074—30.2%
——9——CVE-2025-12203—30.2%
——9——CVE-2026-151886.3 MED30.2%
——9A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is the function EditEmployeeProfileAPIView of the file accounts/api/views.py of the component Employee Dashboard Endpoint. This manipulation of the argument role causes improper access controls. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.71dCVE-2026-15318—30.2%
——9——CVE-2026-55620—30.2%
——9——CVE-2013-0190—30.2%
——9——CVE-2026-10711—30.2%
——9——CVE-2026-161976.3 MED30.2%
——9A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The reported GitHub issue was closed automatically due to inactivity.60dCVE-2025-49302—30.2%
——9——CVE-2026-151896.3 MED30.2%
——9A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is the function upload_media of the component mcp-whatsapp. Such manipulation of the argument media_url leads to server-side request forgery. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.16dCVE-2024-12335—30.2%
——9——CVE-2026-2150—30.2%
——9——CVE-2025-37136—30.2%
——9——CVE-2026-924686.5 MED30.2%
——9zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers can query arbitrary indices including sys_user to retrieve sensitive user records and password hashes without proper access controls.2dCVE-2024-32769—30.2%
——9——CVE-2018-8853—30.2%
——9——CVE-2026-91148.8 HIG30.2%
——9Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)57dCVE-2025-12223—30.2%
——9——CVE-2025-58580—30.2%
——9——CVE-2023-37467—30.2%
——9——CVE-2026-49056—30.2%
——9——CVE-2026-123956.5 MED30.2%
——9The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with a subscriber-level (self-registerable) account to perform SQL injection attacks.64dCVE-2025-28197—30.2%
——9——CVE-2024-23212—30.2%
——9——CVE-2024-31421—30.2%
——9——CVE-2026-117148.5 HIG30.2%
——9IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.43dCVE-2025-68007—30.2%
——9——CVE-2015-2672—30.2%
——9——CVE-2022-22938—30.2%
——9——CVE-2025-9434—30.2%
——9——CVE-2025-4493—30.2%
——9——CVE-2024-30544—30.2%
——9——CVE-2024-30295—30.2%
——9——CVE-2025-28972—30.2%
——9——CVE-2024-3030—30.2%
——9——