Vulnerabilities exploitable today
377,792in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,647
Distribution · last window
- Critical2,444
- High8,774
- Medium6,908
- Low766
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-25950—29.5%
——9——CVE-2008-5397—29.5%
——9——CVE-2026-25517—29.5%
——9——CVE-2026-663906.1 MED29.5%
——9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket.
This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0.
Users are recommended to upgrade to version 10.10.0, which fixes the issue.44dCVE-2025-27954—29.5%
——9——CVE-2026-785456.6 MED29.5%
——9The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.8dCVE-2023-47184—29.5%
——9——CVE-2026-875828.3 HIG29.5%
——9Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)9dCVE-2022-42397—29.5%
——9——CVE-2024-27715—29.5%
——9——CVE-2009-0870—29.5%
——9——CVE-2025-69871—29.5%
——9——CVE-2024-29793—29.5%
——9——CVE-2019-25418—29.5%
——9——CVE-2024-11461—29.5%
——9——CVE-2026-541788.1 HIG29.5%
——9backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDisk in src/app/Models/Traits/HasUploadFields.php trusts disk-relative paths from clear_<attribute>[] and passes them to Storage::disk()->delete without confirming that the paths are persisted on the current model record. An authenticated user with Update access to a CRUD using this mutator through src/app/Models/Traits/CrudTrait.php can delete another record's attachment, a shared asset, or another operational file on the configured disk by submitting its path. The newer MultipleFiles uploader is not affected because it intersects requested deletions with the record's persisted file list. This flaw does not permit reading the deleted files. The 5.x line remains affected through its final releases. This issue is fixed in versions 6.8.12 and 7.0.35.2dCVE-2019-1731—29.5%
——9——CVE-2026-1552—29.5%
——9——CVE-2025-40992—29.5%
——9——CVE-2026-5423—29.5%
——9@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection can forge arbitrary JWT claims (e.g. sub, roles) in connectionParams.jwt and have them accepted as authenticated identity for the purposes of @authentication and @subscriptionsAuthorization directive evaluation. This allows a fully unauthenticated attacker to receive subscription events that should be restricted to specific authenticated roles/users.
Upgrade the library to versions 7.5.6+ or 5.12.14+. v6 is end-of-life and will not receive a fix.32dCVE-2022-42398—29.5%
——9——CVE-2026-6916—29.5%
——9——CVE-2018-14983—29.5%
——9——CVE-2022-42404—29.5%
——9——CVE-2025-54364—29.5%
——9——CVE-2024-53798—29.5%
——9——CVE-2024-3774—29.4%
——9——CVE-2021-30306.1 MED29.4%
——9Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a victim in a browser session authenticated to a site running the vulnerable component, executes arbitrary JavaScript in the security context of that site.14hCVE-2021-47779—29.5%
——9——CVE-2019-25416—29.5%
——9——CVE-2026-40655.4 MED29.5%
——9The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (which requires unfiltered_html capability), and several controller actions only validate the nonce (validateToken()) without calling validatePermission(). This makes it possible for authenticated attackers, with Contributor-level access and above, to enumerate slider metadata and create, modify, and delete image storage records by obtaining the nextend_nonce exposed on post editor pages.56dCVE-2025-1761—29.5%
——9——CVE-2023-32237—29.5%
——9——CVE-2009-0913—29.5%
——9——CVE-2022-42392—29.5%
——9——CVE-2024-32604—29.5%
——9——CVE-2022-41146—29.5%
——9——CVE-2024-30483—29.5%
——9——CVE-2022-42800—29.5%
——9——CVE-2024-12323—29.5%
——9——