Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-67520—26.7%
——8——CVE-2013-2890—26.7%
——8——CVE-2026-44482—26.7%
——8——CVE-2004-1085—26.7%
——8——CVE-2024-7242—26.7%
——8——CVE-2026-73078—26.7%
——8Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840.6dCVE-2026-856917.5 HIG26.7%
——8MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses directly from the JSON response.5dCVE-2026-92354.3 MED26.7%
——8The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including, 2.2.3. These functions are wired to the wp_ajax_dhlpwc_label_create and wp_ajax_dhlpwc_label_delete hooks and act on an attacker-supplied post_id (WooCommerce order ID). This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or delete DHL shipping labels associated with any WooCommerce order on the site.68dCVE-2025-43229—26.7%
——8——CVE-2021-29626—26.7%
——8——CVE-2026-26322—26.7%
——8——CVE-2020-3379—26.7%
——8——CVE-2023-48013—26.7%
——8——CVE-2026-822669.8 CRI26.7%
——8Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.15dCVE-2015-5043—26.7%
——8——CVE-2025-53501—26.7%
——8——CVE-2024-13493—26.7%
——8——CVE-2025-62015—26.7%
——8——CVE-2023-49258—26.7%
——8——CVE-2005-2584—26.7%
——8——CVE-2026-58277.3 HIG26.7%
——8A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /question-function.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.54dCVE-2026-51304—26.7%
——8Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.47dCVE-2015-3321—26.7%
——8——CVE-2026-6306—26.7%
——8——CVE-2025-21161—26.7%
——8——CVE-2025-40645—26.7%
——8——CVE-2025-66451—26.7%
——8——CVE-2021-25142—26.7%
——8——CVE-2024-40806—26.7%
——8——CVE-2020-0114—26.7%
——8——CVE-2026-92404.3 MED26.7%
——8The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateShippingMethod() function (registered to the wp_ajax_lpc_order_affect AJAX action) in versions up to, and including, 2.9.0. This is due to the handler performing no current_user_can() capability check and no nonce verification before reading an attacker-supplied order_id and modifying that order's shipping method, pickup-point meta, and shipping address. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or modify the shipment information (shipping method, pickup relay data, and shipping address) of arbitrary WooCommerce orders, including orders placed by other users.68dCVE-2026-597094.3 MED26.7%
——8Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can assign or remove tags on victim holdings, corrupting portfolio categorization and reports.67dCVE-2022-26696—26.7%
——8——CVE-2025-25042—26.7%
——8——CVE-2021-21785—26.7%
——8——CVE-2026-21950—26.7%
——8——CVE-2026-608056.2 MED26.7%
——8Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Cost Management. CVSS 3.1 Base Score 6.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L).30dCVE-2024-6074—26.7%
——8——CVE-2024-7381—26.7%
——8——CVE-2022-38865—26.7%
——8——