Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,321
- High8,308
- Medium6,572
- Low708
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-68007—30.2%
——9——CVE-2026-123956.5 MED30.2%
——9The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with a subscriber-level (self-registerable) account to perform SQL injection attacks.64dCVE-2024-31421—30.2%
——9——CVE-2023-38885—30.2%
——9——CVE-2025-62863—30.2%
——9——CVE-2025-52910—30.2%
——9——CVE-2026-322279.8 CRI30.2%
——9SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are recommended to upgrade to version 2.9.0, which fixes the issue.32dCVE-2025-56226—30.2%
——9——CVE-2026-154508.1 HIG30.2%
——9The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX handler that lets the same authenticated user store an arbitrary value in the target 'location' column (wp_kses() only strips HTML tags and does not neutralize path traversal or absolute paths). This makes it possible for authenticated attackers, with admin-level access and above, to delete arbitrary files on the affected site's server, including wp-config. When the plugin's user-level option is configured to something else, this may be exploitable with lower privileges.37dCVE-2024-33545—30.2%
——9——CVE-2024-7826—30.2%
——9——CVE-2020-18416—30.2%
——9——CVE-2021-4202—30.2%
——9——CVE-2025-9434—30.2%
——9——CVE-2024-32799—30.2%
——9——CVE-2014-4659—30.2%
——9——CVE-2024-7825—30.2%
——9——CVE-2013-7348—30.2%
——9——CVE-2024-30965—30.2%
——9——CVE-2026-45570—30.2%
——9——CVE-2024-48343—30.2%
——9——CVE-2018-10593—30.2%
——9——CVE-2024-13955—30.2%
——9——CVE-2026-22264—30.2%
——9——CVE-2024-31489—30.2%
——9——CVE-2025-52731—30.2%
——9——CVE-2023-21900—30.2%
——9——CVE-2024-21590—30.2%
——9——CVE-2025-4493—30.2%
——9——CVE-2026-41040—30.2%
——9——CVE-2025-28972—30.2%
——9——CVE-2026-49056—30.2%
——9——CVE-2024-3030—30.2%
——9——CVE-2024-30544—30.2%
——9——CVE-2024-30295—30.2%
——9——CVE-2026-538718.1 HIG30.2%
——9Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass profile-scoped authorization checks and access sessions, files, and resources across different profiles.1dCVE-2026-792167.5 HIG30.2%
——9Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)23dCVE-2024-3862—30.2%
——9——CVE-2026-420017.5 HIG30.2%
——9Insufficient Validation of Autoprimary SOA Queries57dCVE-2025-12657—30.2%
——9——