Vulnerabilities exploitable today
373,224in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,252
- High8,221
- Medium6,136
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-59344—25.0%
——7——CVE-2026-15810—25.0%
——7A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted URL.
Looker-hosted and Self-hosted were found to be vulnerable.
This issue has already been mitigated for Looker-hosted instances. No user action is required for these.
Self-hosted instances must be upgraded to the patched versions: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+.49dCVE-2025-10070—25.0%
——7——CVE-2025-10071—25.0%
——7——CVE-2007-2729—25.0%
——7——CVE-2026-3368—25.0%
——7——CVE-2025-12289—25.0%
——7——CVE-2026-577688.2 HIG25.0%
——7Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.63dCVE-2025-52752—25.0%
——7——CVE-2023-22599—24.9%
——7——CVE-2021-47703—25.0%
——7——CVE-2003-0214—24.9%
——7——CVE-2002-1387—24.9%
——7——CVE-2024-32913—24.9%
——7——CVE-2025-46386—24.9%
——7——CVE-2003-0337—24.9%
——7——CVE-2023-42242—24.9%
——7——CVE-2025-9683—24.9%
——7——CVE-2018-3562—24.9%
——7——CVE-2003-0261—24.9%
——7——CVE-2024-45114—24.9%
——7——CVE-2026-115805.5 MED24.9%
——7The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.61dCVE-2003-0606—24.9%
——7——CVE-2023-42238—24.9%
——7——CVE-2000-0433—24.9%
——7——CVE-2025-6089—24.9%
——7——CVE-2003-0359—24.9%
——7——CVE-2025-653369.8 CRI24.9%
——7Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.45dCVE-2026-574057.1 HIG24.9%
——7Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through <= 1.7.1.63dCVE-2025-11438—24.9%
——7——CVE-2024-25142—24.9%
——7——CVE-2025-54352—24.9%
——7——CVE-2006-5871—24.9%
——7——CVE-2025-9682—24.9%
——7——CVE-2026-597998.8 HIG24.9%
——7Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow.
This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.18dCVE-2024-13832—24.9%
——7——CVE-2024-5259—24.9%
——7——CVE-2013-0350—24.9%
——7——CVE-2026-4473—24.9%
——7——CVE-2023-49099—24.9%
——7——