Vulnerabilities exploitable today
372,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,214
- High8,131
- Medium6,162
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-343956.5 MED24.3%
——7WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform users with their personal information and wallet balances to any authenticated user. The endpoint checks User::isLogged() but does not check User::isAdmin(), so any registered user can dump the full user database. At time of publication, there are no publicly available patches.50dCVE-2024-36063—24.3%
——7——CVE-2024-3277—24.3%
——7——CVE-2025-63829—24.3%
——7——CVE-2026-32631—24.3%
——7——CVE-2026-79921—24.3%
——7amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.15dCVE-2026-142067.5 HIG24.3%
——7The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.17dCVE-2025-43915—24.3%
——7——CVE-2026-166027.5 HIG24.3%
——7The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured.17dCVE-2024-49808—24.3%
——7——CVE-2024-22190—24.3%
——7——CVE-2023-44986—24.3%
——7——CVE-2012-5564—24.3%
——7——CVE-2026-175417.5 HIG24.3%
——7The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.17dCVE-2022-43040—24.3%
——7——CVE-2023-50830—24.3%
——7——CVE-2026-4564—24.3%
——7——CVE-2010-4458—24.3%
——7——CVE-2026-326625.3 MED24.3%
——7Development and test API endpoints are present that mirror production functionality.50dCVE-2022-47654—24.3%
——7——CVE-2026-9092—24.3%
——7——CVE-2026-768276.8 MED24.3%
——7A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.7dCVE-2023-47453—24.3%
——7——CVE-2024-24841—24.3%
——7——CVE-2023-1514—24.3%
——7——CVE-2024-35764—24.3%
——7——CVE-2026-190847.5 HIG24.3%
——7The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.15dCVE-2025-46722—24.3%
——7——CVE-2024-10503—24.3%
——7——CVE-2026-331148.4 HIG24.3%
——7Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.50dCVE-2022-28385—24.3%
——7——CVE-2026-402918.8 HIG24.3%
——7Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in the PUT /api/users/{id} endpoint allows any authenticated user with ROLE_STUDENT to escalate their privileges to ROLE_ADMIN by modifying the roles field on their own user record. The API Platform security expression is_granted('EDIT', object) only verifies record ownership, and the roles field is included in the writable serialization group, enabling any user to set arbitrary roles such as ROLE_ADMIN. Successful exploitation grants full administrative control of the platform, including access to all courses, user data, grades, and administrative settings. This issue has been fixed in version 2.0.0-RC.3.50dCVE-2025-24124—24.3%
——7——CVE-2025-2806—24.3%
——7——CVE-2021-45339—24.3%
——7——CVE-2008-5746—24.3%
——7——CVE-2025-67478—24.3%
——7——CVE-2026-44385.4 MED24.3%
——7Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.60dCVE-2026-25325—24.3%
——7——CVE-2022-22528—24.3%
——7——