Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-3134—25.5%
——8——CVE-2025-32352—25.5%
——8——CVE-2024-7355—25.5%
——8——CVE-2025-23849—25.5%
——8——CVE-2025-59948—25.5%
——8——CVE-2026-580567.6 HIG25.5%
——8RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and display-capture handlers, acting outside its granted scope.59dCVE-2024-10179—25.5%
——8——CVE-2026-734046.5 MED25.5%
——8Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.26dCVE-2026-28913—25.5%
——8——CVE-2026-4319—25.5%
——8——CVE-2026-25993—25.5%
——8——CVE-2024-2933—25.5%
——8——CVE-2026-30496—25.5%
——8——CVE-2024-12733—25.5%
——8——CVE-2024-3519—25.5%
——8——CVE-2026-279996.5 MED25.5%
——8Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.32dCVE-2021-3592—25.5%
——8——CVE-2024-41960—25.5%
——8——CVE-2019-7307—25.5%
——8——CVE-2024-54048—25.5%
——8——CVE-2026-5161—25.5%
——8——CVE-2025-6432—25.5%
——8——CVE-2026-185509.8 CRI25.5%
——8The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri_reset_password()` function, which allows empty attacker-supplied reset tokens to match empty or unset `sb_password_forget_token` user meta values. This makes it possible for unauthenticated attackers to reset the password of any user, including administrators, and gain access to their account.13dCVE-2026-152816.5 MED25.5%
——8The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This is due to insufficient validation on the objectId value stored in the saveAjaxAttachmentData() function and subsequent unparameterized concatenation in the addQueryExcludedPostFilter() function — the stored value is later retrieved from the database and used as an array key, then directly imploded into a SQL NOT IN() clause without integer casting or prepared statements. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.34dCVE-2024-27350—25.5%
——8——CVE-2024-54046—25.5%
——8——CVE-2025-1721—25.5%
——8——CVE-2026-753389.8 CRI25.5%
——8disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any anonymous attacker can read every configuration item and configuration file managed by the config center.6dCVE-2025-12189—25.5%
——8——CVE-2024-2253—25.5%
——8——CVE-2026-73427—25.5%
——8Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into an editor using the fallback Level0InputController, such as an embedded WebView without Input Events Level 2 support. The StringPiece.fromJSON method trusts href attributes from the JSON payload without sanitization, allowing a draggable element containing a javascript: URI to bypass DOMPurify sanitization and inject executable JavaScript into the DOM. Exploitation requires the victim to drag and drop attacker-controlled content, and server-side HTML sanitization can neutralize the payload on save. This issue is fixed in version 2.1.18.6dCVE-2026-4924—25.5%
——8——CVE-2010-5179—25.5%
——8——CVE-2022-29934—25.5%
——8——CVE-2022-32945—25.5%
——8——CVE-2025-522227.5 HIG25.5%
——8D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters in the radius_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.52dCVE-2026-3261—25.5%
——8——CVE-2022-30625—25.5%
——8——CVE-2026-21959—25.5%
——8——CVE-2026-601797.4 HIG25.5%
——8Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).40d