Vulnerabilities exploitable today
373,010in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,220
- High8,128
- Medium6,188
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-175337.2 HIG24.3%
——7The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.17dCVE-2026-146154.3 MED24.3%
——7A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.32dCVE-2022-2869—24.3%
——7——CVE-2009-0607—24.3%
——7——CVE-2021-39742—24.3%
——7——CVE-2025-10916—24.3%
——7——CVE-2026-876128.8 HIG24.3%
——7Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)3dCVE-2026-418483.7 LOW24.3%
——7Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path).
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.52dCVE-2026-75579.1 CRI24.3%
——7An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.9dCVE-2013-2297—24.3%
——7——CVE-2026-34747—24.3%
——7——CVE-2023-7287—24.3%
——7——CVE-2015-0430—24.3%
——7——CVE-2005-1407—24.3%
——7——CVE-2025-3688—24.3%
——7——CVE-2022-2867—24.3%
——7——CVE-2025-63288—24.3%
——7——CVE-2022-36670—24.3%
——7——CVE-2025-21191—24.3%
——7——CVE-2010-4512—24.3%
——7——CVE-2025-43768—24.3%
——7——CVE-2010-2237—24.3%
——7——CVE-2005-2211—24.3%
——7——CVE-2025-137934.3 MED24.3%
——7A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.10dCVE-2024-5674—24.3%
——7——CVE-2013-2794—24.3%
——7——CVE-2024-5382—24.3%
——7——CVE-2025-3951—24.3%
——7——CVE-2022-38454—24.3%
——7——CVE-2025-13238—24.3%
——7——CVE-2025-48480—24.3%
——7——CVE-2017-1000201—24.3%
——7——CVE-2025-8604—24.3%
——7——CVE-2019-12176—24.3%
——7——CVE-2024-22192—24.3%
——7——CVE-2022-2868—24.3%
——7——CVE-2025-67975—24.3%
——7——CVE-2024-8250—24.3%
——7——CVE-2026-63337—24.3%
——7The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system.describe response and passes it through JSONUtil.tryFill, setJavaReturnType, and computeReturnTypeAsJavaClass to Class.forName(javaReturnType) with initialization enabled. An attacker able to answer the JsonRpcClient request through a shared broker or network interception can select a class already present in the victim JVM and trigger its static initializer, while JsonRpcClient.java later passes getReturnType output to mapper.parse and may also create type confusion. Successful exploitation can affect confidentiality, integrity, and availability in the client process. This issue is fixed in version 5.33.0.25dCVE-2016-1271—24.3%
——7——