Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,217
- High8,135
- Medium6,162
- Low606
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-21838—22.9%
——7——CVE-2026-629277.5 HIG22.9%
——7In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.36dCVE-2024-12617—22.9%
——7——CVE-2026-2511—22.9%
——7——CVE-2026-47835—22.9%
——7——CVE-2024-54218—22.9%
——7——CVE-2026-147857.5 HIG22.9%
——7The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.44dCVE-2025-10235—22.9%
——7——CVE-2025-41015—22.9%
——7——CVE-2013-0415—22.9%
——7——CVE-2026-655729.8 CRI22.9%
——7Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.29dCVE-2007-4027—22.9%
——7——CVE-2024-37175—22.9%
——7——CVE-2026-655769.8 CRI22.9%
——7Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.29dCVE-2025-63049—22.9%
——7——CVE-2026-655719.8 CRI22.9%
——7Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.29dCVE-2024-1328—22.9%
——7——CVE-2026-822698.1 HIG22.9%
——7Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.13dCVE-2026-655739.8 CRI22.9%
——7Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.29dCVE-2024-34127—22.9%
——7——CVE-2026-33134—22.9%
——7——CVE-2016-7440—22.9%
——7——CVE-2025-8545—22.9%
——7——CVE-2025-65405—22.9%
——7——CVE-2026-655779.8 CRI22.9%
——7Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.29dCVE-2014-0148—22.9%
——7——CVE-2023-33544—22.9%
——7——CVE-2025-4686—22.9%
——7——CVE-2025-25197—22.9%
——7——CVE-2025-8425—22.9%
——7——CVE-2026-655569.8 CRI22.9%
——7Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.29dCVE-2026-655749.8 CRI22.9%
——7Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.29dCVE-2026-655759.8 CRI22.9%
——7Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.29dCVE-2025-50477—22.9%
——7——CVE-2025-10758—22.9%
——7——CVE-2025-13958.2 HIG22.9%
——7Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping.
This issue affects HeyGarson: through 30012026.
NOTE: The vendor was contacted and it was learned that the product is not supported.34dCVE-2026-145746.5 MED22.9%
——7In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). Because this function is invoked by `PreferenceServiceImpl.doResolve` for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (`.theia/settings.json` or `.vscode/settings.json`) can pollute `Object.prototype` when the user opens the workspace, potentially altering application logic across the Theia process.34dCVE-2026-128007.5 HIG22.9%
——7The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint in versions up to, and including, 6.2.0. This is due to insufficient escaping on the user-supplied parameter, which is interpolated directly into a raw SQL query string in the CouponCodes::find() method without use of $wpdb->prepare() or esc_sql(). This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.44dCVE-2025-8790—22.9%
——7——CVE-2026-819948.2 HIG22.9%
——7Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.1d