Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,286
- High8,401
- Medium6,423
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-33935—23.0%
——7——CVE-2019-15470—23.0%
——7——CVE-2019-11145—23.0%
——7——CVE-2010-2400—23.0%
——7——CVE-2024-5142—23.0%
——7——CVE-2026-588229.8 CRI23.0%
——7In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.2dCVE-2026-489126.5 MED23.0%
——7Improper Input Validation vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs.
Users are recommended to upgrade to version 2.0.2, which fixes the issue.35dCVE-2014-6881—23.0%
——7——CVE-2026-109118.3 HIG23.0%
——7Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)50dCVE-2024-7713—23.0%
——7——CVE-2025-42876—23.0%
——7——CVE-2026-788954.3 MED23.0%
——7Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)14dCVE-2026-109208.3 HIG23.0%
——7Insufficient validation of untrusted input in WebShare in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)50dCVE-2024-31980—23.0%
——7——CVE-2026-44874—23.0%
——7——CVE-2026-23972—23.0%
——7——CVE-2024-45510—23.0%
——7——CVE-2026-7587—23.0%
——7——CVE-2026-667775.9 MED23.0%
——7SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their assigned scope. Successful exploitation could allow the attacker to read sensitive data and perform limited modifications on protected resources, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.2dCVE-2023-37539—23.0%
——7——CVE-2018-253728.2 HIG23.0%
——7MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the email parameter. Attackers can submit crafted POST requests to the userSignup.php endpoint with SQL payloads in the email field to extract sensitive database information from the backend MySQL database.49dCVE-2026-3906—23.0%
——7——CVE-2019-8775—23.0%
——7——CVE-2025-60269—23.0%
——7——CVE-2010-2399—23.0%
——7——CVE-2021-29707—23.0%
——7——CVE-2023-42894—23.0%
——7——CVE-2025-52454—23.0%
——7——CVE-2026-122995.4 MED23.0%
——7JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.58dCVE-2026-175806.5 MED23.0%
——7The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the register_rest_routes. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive admin-authored editor content — including template markup, CSS code, JavaScript code, and PHP controller variables — for any Layout or Post Selection post on the site.29dCVE-2026-153454.3 MED23.0%
——7The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify configuration options of third-party plugins including ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, and LiteSpeed Cache, as well as the plugin's own API key and account binding. Exploitation requires the respective third-party plugins to be installed, as the impact against those plugins' settings is only reachable when those plugins are present.22dCVE-2019-2389—23.0%
——7——CVE-2023-24380—23.0%
——7——CVE-2026-0927—23.0%
——7——CVE-2025-52453—23.0%
——7——CVE-2020-8682—23.0%
——7——CVE-2025-8660—23.0%
——7——CVE-2023-27461—23.0%
——7——CVE-2019-4572—23.0%
——7——CVE-2026-742455.9 MED23.0%
——7A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure, potentially exposing sensitive data such as usernames, email addresses, IP addresses, and action-specific metadata.21d