Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-9361—25.1%
——8——CVE-2026-733777.5 HIG25.1%
——8Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.26dCVE-2024-9653—25.1%
——8——CVE-2021-41278—25.1%
——8——CVE-2026-846399.1 CRI25.1%
——8Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.12dCVE-2026-369587.5 HIG25.1%
——8A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the router web interface to become unresponsive and may require manual reboot to restore normal operation.72dCVE-2025-12939—25.1%
——8——CVE-2026-22479—25.1%
——8——CVE-2025-64639—25.1%
——8——CVE-2024-32566—25.1%
——8——CVE-2026-6572—25.1%
——8——CVE-2026-709115.3 MED25.1%
——8Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).22dCVE-2026-41671—25.1%
——8——CVE-2025-69771—25.1%
——8——CVE-2020-12324—25.1%
——8——CVE-2024-23210—25.1%
——8——CVE-2025-156628.6 HIG25.1%
——8The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources.50dCVE-1999-0473—25.1%
——8——CVE-2024-47442—25.1%
——8——CVE-2025-20214—25.1%
——8——CVE-2025-5018—25.1%
——8——CVE-2024-22361—25.1%
——8——CVE-2020-12318—25.1%
——8——CVE-2020-37014—25.1%
——8——CVE-2026-0403—25.1%
——8——CVE-2024-3883—25.1%
——8——CVE-2025-13057—25.1%
——8——CVE-2025-13396—25.1%
——8——CVE-2026-24410—25.1%
——8——CVE-2025-47975—25.1%
——8——CVE-2011-3565—25.1%
——8——CVE-2026-888678.7 HIG25.1%
——8WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Category::setName() and Category::setIconClass(), which store the values without sanitization (setName only truncates to 45 characters). The category name is later echoed as HTML text and iconClass is echoed into a class attribute in view/modeYoutubeBottom.php and in Gallery cards (plugin/Gallery/functions.php). When the CustomizeUser option usersCanCreateNewCategories is enabled, any authenticated user with canUpload permission (granted by default via self-registration) can create a category containing a JavaScript payload; the payload then executes in the browser of any visitor, including administrators, who views a watch page or gallery entry for a video assigned to that category, allowing actions such as authenticated requests with the victim's session. The issue was unpatched at the time of reporting.5dCVE-2026-118695.3 MED25.1%
——8The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.68dCVE-2020-124014.7 MED25.1%
——8During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.27dCVE-2020-4311—25.1%
——8——CVE-2020-12336—25.1%
——8——CVE-2021-39081—25.1%
——8——CVE-2021-30938—25.1%
——8——CVE-2025-6427—25.1%
——8——CVE-2008-5375—25.1%
——8——