Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-8826—29.5%
——9——CVE-2026-88921—29.4%
——9MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the convert_markdown_to_pdf module. The attribute(), objectAttribute(), object(), and tag() methods interpolated user-controlled fields (attribute type, attribute value, object name, object relation, tag name, tag colour, and tag text colour) directly into HTML templates without applying HTML entity encoding. An authenticated user with the ability to create or modify MISP attributes, objects, or tags could embed arbitrary HTML markup in these fields. When a report containing such elements was exported to PDF, the unescaped content was rendered as live HTML rather than inert text, potentially injecting script tags, breaking the document structure, or altering the visual content of the exported report. Additionally, the attribute() method contained a template with hardcoded sample values ("domain-ip" and "google.com") instead of format placeholders, meaning every plain attribute reference in a PDF displayed the sample text rather than the actual indicator value, constituting a data-integrity defect in the exported document. The vulnerability requires an authenticated actor with write access to MISP elements and a subsequent PDF export of a report referencing those elements. The security impact is primarily to the integrity of the exported document and, depending on the HTML-to-PDF rendering engine, potential execution of injected markup during the conversion step.
Version affected: ≤2.5.458dCVE-2026-22559—29.5%
——9——CVE-2023-51733—29.5%
——9——CVE-2024-22153—29.5%
——9——CVE-2002-0165—29.5%
——9——CVE-2009-4664—29.5%
——9——CVE-2025-32020—29.5%
——9——CVE-1999-1126—29.5%
——9——CVE-2005-0120—29.5%
——9——CVE-2023-51736—29.5%
——9——CVE-2010-3159—29.5%
——9——CVE-2025-15329—29.5%
——9——CVE-2020-37044—29.5%
——9——CVE-2026-27599—29.5%
——9——CVE-2026-98517.2 HIG29.5%
——9The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint, where the handler only validates a nonce and the dispatcher invokes Schedule::updateUser() with the $administrator argument hard-coded to 1, bypassing the only owner-restriction check inside that function and allowing the target user to be determined solely by attacker-supplied input passed directly to wp_update_user(). This makes it possible for authenticated attackers, with Editor-level access and above, to change the email address and password of any account, including Administrator accounts, resulting in a full site takeover.57dCVE-2026-638898.1 HIG29.5%
——9In the Linux kernel, the following vulnerability has been resolved:
scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS
frame to an lpfc or qla2xxx Linux initiator can trigger a non-return in
the generic FC transport. This is not a local userspace or IP network
path; the attacker must be able to inject fabric traffic, for example as
a compromised switch or fabric controller, or as a same-zone N_Port on a
fabric that permits source spoofing.
The Link-Integrity and Peer-Congestion FPIN walkers used a u8 loop
counter against the 32-bit on-wire pname_count field, and did not bound
pname_count by the descriptor body already validated by the TLV walker.
A pname_count of 256 therefore wraps the counter and keeps the loop
condition true indefinitely.
Factor the shared pname_list[] walk into one helper, widen the counter
to u32, and clamp pname_count against the entries that fit in the
descriptor body before iterating.52dCVE-2023-28783—29.5%
——9——CVE-2023-51725—29.5%
——9——CVE-2023-23786—29.5%
——9——CVE-2023-51723—29.5%
——9——CVE-2023-51726—29.5%
——9——CVE-2019-5291—29.5%
——9——CVE-2026-190644.3 MED29.5%
——9A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely.36dCVE-2024-28022—29.4%
——9——CVE-2016-6310—29.4%
——9——CVE-2020-7534—29.4%
——9——CVE-2025-48805—29.4%
——9——CVE-2026-1375—29.4%
——9——CVE-2005-2742—29.4%
——9——CVE-2025-0560—29.4%
——9——CVE-2008-0836—29.4%
——9——CVE-2023-25015—29.4%
——9——CVE-2011-1356—29.4%
——9——CVE-2025-6720—29.4%
——9——CVE-2026-3371—29.4%
——9——CVE-2026-614545.3 MED29.4%
——9The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime environment type, and exact Grav and Admin2 version numbers, allowing an unauthenticated attacker to fingerprint the deployment and select version-specific exploits without reconnaissance.66dCVE-2007-6225—29.4%
——9——CVE-2021-36338—29.4%
——9——CVE-2025-49661—29.4%
——9——