Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,225
- High7,948
- Medium6,436
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-739988.5 HIG27.4%
——8Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.27dCVE-2025-2511—27.4%
——8——CVE-2022-25662—27.4%
——8——CVE-2026-341038.8 HIG27.4%
——8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents.23dCVE-2024-27997—27.4%
——8——CVE-2026-154017.2 HIG27.4%
——8The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vbfX custom-field value is stored via the public-facing saveorder task, which has no capability or authentication check enforced by default, enabling fully unauthenticated submission of malicious payloads.54dCVE-2022-2449—27.4%
——8——CVE-2018-4244—27.4%
——8——CVE-2024-39094—27.4%
——8——CVE-2026-341058.8 HIG27.4%
——8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents.23dCVE-2017-2452—27.4%
——8——CVE-2019-19350—27.4%
——8——CVE-2026-44603—27.4%
——8——CVE-2004-0515—27.4%
——8——CVE-2018-12222—27.4%
——8——CVE-2024-8433—27.4%
——8——CVE-2024-34661—27.4%
——8——CVE-2026-325648.5 HIG27.4%
——8Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.19dCVE-2020-8002—27.4%
——8——CVE-2026-172076.5 MED27.4%
——8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.8dCVE-2026-325508.5 HIG27.4%
——8Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.19dCVE-2024-5205—27.4%
——8——CVE-2025-11624—27.4%
——8——CVE-2025-65781—27.4%
——8——CVE-2024-10527—27.4%
——8——CVE-2024-9543—27.4%
——8——CVE-2026-595606.5 MED27.4%
——8Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.51dCVE-2023-21989—27.4%
——8——CVE-2016-0235—27.4%
——8——CVE-2004-1108—27.4%
——8——CVE-2004-0517—27.4%
——8——CVE-2004-0516—27.4%
——8——CVE-2008-5843—27.4%
——8——CVE-2026-257144.3 MED27.4%
——8Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.71dCVE-2024-6539—27.4%
——8——CVE-2026-33297—27.4%
——8——CVE-2026-34158.7 HIG27.4%
——8The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content during validation operations. This behavior can occur when an attacker supplies crafted XML payloads to the relevant mediator flows with sufficient privileges.
Successful exploitation may allow a highly privileged actor to read files accessible within the server hosting the affected product. Additionally, it may be possible to trigger outbound requests to unintended internal or external locations, depending on the server environment and network configuration. Specially crafted XML payloads can also lead to excessive resource consumption during parsing, impacting the availability of the product.16dCVE-2026-517425.9 MED27.4%
——8Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.15dCVE-2026-558734.3 MED27.4%
——8SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs. This issue is fixed in version 4.34.70dCVE-2026-517485.9 MED27.4%
——8Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.15d