Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-15417—26.1%
——8——CVE-2024-41699—26.1%
——8——CVE-2024-3633—26.1%
——8——CVE-2026-76406.4 MED26.1%
——8The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortcode in all versions up to, and including, 8.3.5. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.62dCVE-2025-64103—26.1%
——8——CVE-2023-53161—26.1%
——8——CVE-2024-13380—26.1%
——8——CVE-2025-46844—26.1%
——8——CVE-2024-10101—26.1%
——8——CVE-2006-1009—26.1%
——8——CVE-2003-1049—26.1%
——8——CVE-2005-0542—26.1%
——8——CVE-2012-2103—26.1%
——8——CVE-2016-5525—26.1%
——8——CVE-2021-30922—26.1%
——8——CVE-2025-40689—26.1%
——8——CVE-2026-1856—26.1%
——8——CVE-2004-0435—26.1%
——8——CVE-2018-7471—26.1%
——8——CVE-2004-0126—26.1%
——8——CVE-2009-0313—26.1%
——8——CVE-2020-5684—26.1%
——8——CVE-2026-1489—26.1%
——8——CVE-2025-4994—26.1%
——8The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an attacker within wireless range can gain unauthorized administrative access to the device configuration.70dCVE-2026-1135—26.1%
——8——CVE-2021-29963—26.1%
——8——CVE-2024-56114—26.1%
——8——CVE-2024-30552—26.1%
——8——CVE-2010-2712—26.1%
——8——CVE-2019-19353—26.1%
——8——CVE-2005-1856—26.1%
——8——CVE-2018-6978—26.1%
——8——CVE-2021-22159—26.1%
——8——CVE-2022-25255—26.1%
——8——CVE-2026-141518.3 HIG26.1%
——8Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)76dCVE-2026-44212—26.1%
——8——CVE-2024-30555—26.1%
——8——CVE-2026-597699.1 CRI26.1%
——8FA-50 all versions contain hard-coded credentials.
An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.18dCVE-2024-29118—26.1%
——8——CVE-2014-9717—26.1%
——8——