Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-8720—26.5%
——8——CVE-2026-31800—26.5%
——8——CVE-2026-153244.4 MED26.5%
——8The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.60dCVE-2026-97384.4 MED26.5%
——8The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.64dCVE-2026-374607.5 HIG26.5%
——8Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.55dCVE-2020-13867—26.5%
——8——CVE-2023-42922—26.5%
——8——CVE-2024-24255—26.5%
——8——CVE-2019-17437—26.5%
——8——CVE-2025-10625—26.5%
——8——CVE-2020-3835—26.5%
——8——CVE-2008-0038—26.5%
——8——CVE-2017-5967—26.5%
——8——CVE-2025-58451—26.5%
——8——CVE-2025-22704—26.5%
——8——CVE-2025-10299—26.5%
——8——CVE-2025-22730—26.5%
——8——CVE-2026-800989.3 CRI26.5%
——8Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.7dCVE-2026-689515.3 MED26.5%
——8GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data.15dCVE-2019-25639—26.5%
——8——CVE-2025-41754—26.5%
——8——CVE-2022-48509—26.5%
——8——CVE-2026-286188.8 HIG26.5%
——8In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.12hCVE-2026-6929—26.5%
——8——CVE-2023-26370—26.5%
——8——CVE-2006-5649—26.5%
——8——CVE-2010-4446—26.5%
——8——CVE-2023-39610—26.5%
——8——CVE-2014-8833—26.5%
——8——CVE-2025-62085—26.5%
——8——CVE-2025-24541—26.5%
——8——CVE-2025-43589—26.5%
——8——CVE-2026-853815.3 MED26.5%
——8A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Home/Controller/ChapterController.class.php of the component Chapter Controller. Such manipulation of the argument content leads to authorization bypass. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.7dCVE-2020-0599—26.5%
——8——CVE-2019-1596—26.5%
——8——CVE-2018-25203—26.5%
——8——CVE-2024-5946—26.5%
——8——CVE-2025-40670—26.5%
——8——CVE-2026-692777.8 HIG26.5%
——8Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.6dCVE-2025-15367—26.5%
——8——