Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-133927.2 HIG29.5%
——9The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code/file editing, reach host-level code execution beyond the privileges the network grants them.23dCVE-2024-24459—29.5%
——9——CVE-2025-15210—29.5%
——9——CVE-2026-7819—29.5%
——9——CVE-2025-60540—29.5%
——9——CVE-2024-48448—29.5%
——9——CVE-2026-44011—29.5%
——9——CVE-2024-29813—29.5%
——9——CVE-2024-30452—29.5%
——9——CVE-2025-13244—29.5%
——9——CVE-2024-20377—29.5%
——9——CVE-2020-5833—29.5%
——9——CVE-2024-52967—29.5%
——9——CVE-2025-53681—29.5%
——9——CVE-2014-5033—29.5%
——9——CVE-2025-7689—29.5%
——9——CVE-2024-10493—29.5%
——9——CVE-2023-51728—29.5%
——9——CVE-2025-31100—29.5%
——9——CVE-2023-47070—29.5%
——9——CVE-2001-0412—29.5%
——9——CVE-2024-11811—29.5%
——9——CVE-2016-1738—29.5%
——9——CVE-2006-5007—29.5%
——9——CVE-2023-388997.8 HIG29.5%
——9SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.71dCVE-2023-41949—29.5%
——9——CVE-2024-28805—29.5%
——9——CVE-2024-41809—29.5%
——9——CVE-2023-37538—29.5%
——9——CVE-2024-12622—29.5%
——9——CVE-2024-10980—29.5%
——9——CVE-2023-47073—29.5%
——9——CVE-2021-27379—29.5%
——9——CVE-2025-20367—29.5%
——9——CVE-2025-0511—29.5%
——9——CVE-2026-799878.8 HIG29.5%
——9A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.7dCVE-2017-13166—29.5%
——9——CVE-2023-51729—29.5%
——9——CVE-2019-18256—29.5%
——9——CVE-2020-29193—29.5%
——9——