Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-28920—25.9%
——8——CVE-2010-4076—25.9%
——8——CVE-2026-826054.3 MED25.9%
——8A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.16dCVE-2026-781796.3 MED25.9%
——8A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of object prototype attributes. The attack can be launched remotely.22dCVE-2025-58616—25.9%
——8——CVE-2026-33909—25.9%
——8——CVE-2026-528338.0 HIG25.9%
——8Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttributes.repositories[] values with the {{ . }} action, which performs no escaping. An attacker can embed a closing brace (}) to break out of the repositories {} block and append arbitrary Groovy statements that execute unconditionally during the Gradle configuration phase. This issue has been patched in version 1.16.5.13dCVE-2017-12840—25.9%
——8——CVE-2024-28761—25.9%
——8——CVE-2024-7424—25.9%
——8——CVE-2025-1046—25.9%
——8——CVE-2026-595115.3 MED25.9%
——8Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data.
This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.71dCVE-2026-76176—25.9%
——8SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the application and retrieve information stored in the database.12dCVE-2025-30743—25.9%
——8——CVE-2025-66214—25.9%
——8——CVE-2026-161064.9 MED25.9%
——8A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.15dCVE-2024-54529—25.9%
——8——CVE-2024-22855—25.9%
——8——CVE-2025-64637—25.9%
——8——CVE-2026-82821—25.9%
——8——CVE-2020-8486—25.9%
——8——CVE-2026-811625.3 MED25.9%
——8Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.6dCVE-2025-55624—25.9%
——8——CVE-2026-577535.3 MED25.9%
——8Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.75dCVE-2025-13660—25.9%
——8——CVE-2026-42275—25.9%
——8——CVE-2024-36364—25.9%
——8——CVE-2026-672145.9 MED25.9%
——8nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.20dCVE-2026-76175—25.9%
——8SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper parameterisation or validation, allowing the query to be manipulated and information to be extracted from the database using SQL injection techniques.12dCVE-2026-655215.3 MED25.9%
——8Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.54dCVE-2024-11390—25.9%
——8——CVE-2026-5240—25.9%
——8——CVE-2023-36854—25.9%
——8——CVE-2024-38069—25.9%
——8——CVE-2023-41805—25.9%
——8——CVE-2026-595195.3 MED25.9%
——8Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data.
This issue affects FormLayer: from n/a through 1.0.6.71dCVE-2026-12439—25.9%
——8——CVE-2026-586007.8 HIG25.9%
——8Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.7dCVE-2026-452457.4 HIG25.9%
——8Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. Attackers can place local or private-network URLs behind hoverable links to route authenticated requests through the daemon, potentially accessing sensitive internal endpoints when users interact with attacker-controlled content.63dCVE-2023-50963—25.9%
——8——