Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,459
- Medium6,415
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-4378—25.9%
——8——CVE-2024-48950—25.9%
——8——CVE-2026-185617.5 HIG25.9%
——8The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString() function; when the parameter is supplied as an array, element zero is used verbatim as the SQL comparison operator and concatenated into the WHERE clause without sanitization, while normalizeAjaxInputData() strips WordPress's magic_quotes protection from the value. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.4dCVE-2011-0813—25.9%
——8——CVE-2024-7791—25.9%
——8——CVE-2026-661394.8 MED25.9%
——8OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.47dCVE-2024-13674—25.9%
——8——CVE-2026-437466.5 MED25.9%
——8A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.22hCVE-2026-577204.3 MED25.9%
——8Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects ThumbPress: from n/a through 6.3.2.76dCVE-2010-3506—25.9%
——8——CVE-2026-71847—25.9%
——8Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released storage. When partial_value reconstructs an incomplete object containing duplicate keys, the duplicate-key warning path calls cursor_position, which dereferences those stale pointers. This results in a heap-use-after-free and can terminate the Ruby process. An attacker who can supply JSON stream data to an application using JSON::ResumableParser may cause process termination when the application calls partial_value on incomplete attacker-controlled input containing duplicate object keys. This issue has been fixed in version 2.21.2.39dCVE-2021-43531—25.9%
——8——CVE-2024-8318—25.9%
——8——CVE-2023-31724—25.9%
——8——CVE-2024-5663—25.9%
——8——CVE-2017-0423—25.9%
——8——CVE-2026-721488.8 HIG25.9%
——8In the Linux kernel, the following vulnerability has been resolved:
dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
The DONE_INT_MASK and ABORT_INT_MASK registers are shared by all DMA
channels, and modifying them requires a read-modify-write sequence.
Because this operation is not atomic, concurrent calls to
dw_edma_v0_core_start() can introduce race conditions if two channels
update these registers simultaneously.
Add a spinlock to serialize access to these registers and prevent race
conditions.
[den: update dw_edma.lock comment]23dCVE-2022-4975—25.9%
——8——CVE-2026-53982—25.9%
——8——CVE-2019-18808—25.9%
——8——CVE-2025-27827—25.9%
——8——CVE-2025-23215—25.9%
——8——CVE-2011-2285—25.9%
——8——CVE-2011-0829—25.9%
——8——CVE-2024-7606—25.9%
——8——CVE-2026-25766—25.9%
——8——CVE-2024-38038—25.9%
——8——CVE-2023-37749—25.9%
——8——CVE-2022-3606—25.9%
——8——CVE-2004-0283—25.9%
——8——CVE-2025-68853—25.9%
——8——CVE-2026-146134.3 MED25.9%
——8A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. The system fails to check if the administrator has permission to see those specific groups. This could allow a restricted administrator to discover "hidden" groups and see their details, such as internal names and custom settings, which might contain sensitive deployment information.15dCVE-2025-712527.5 HIG25.9%
——8In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.57dCVE-2023-37541—25.9%
——8——CVE-2024-24487—25.9%
——8——CVE-2013-5148—25.9%
——8——CVE-2017-2437—25.9%
——8——CVE-2026-708729.1 CRI25.9%
——8Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).22dCVE-2022-36312—25.9%
——8——CVE-2026-585174.3 MED25.9%
——8Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass.
This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.67d