Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,221
- High8,140
- Medium6,166
- Low607
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-6965—22.8%
——7——CVE-2025-26948—22.8%
——7——CVE-2024-13010—22.8%
——7——CVE-2023-21603—22.8%
——7——CVE-2023-50175—22.8%
——7——CVE-2024-12567—22.8%
——7——CVE-2026-27457—22.8%
——7——CVE-2026-40154—22.8%
——7——CVE-2018-17483—22.8%
——7——CVE-2024-10323—22.8%
——7——CVE-2023-43054—22.8%
——7——CVE-2026-12276—22.8%
——7——CVE-2025-8447—22.8%
——7——CVE-2017-0690—22.8%
——7——CVE-2024-26349—22.8%
——7——CVE-2024-8960—22.8%
——7——CVE-2024-55950—22.8%
——7——CVE-2024-11915—22.8%
——7——CVE-2022-40903—22.8%
——7——CVE-2026-118685.3 MED22.8%
——7The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.52dCVE-2026-119665.3 MED22.8%
——7The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete recently-registered, payment-pending user accounts.55dCVE-2026-421376.5 MED22.8%
——7Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. This issue has been patched in versions 4.9.0 and 5.4.0.48dCVE-2024-323893.5 LOW22.8%
——7Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component.55dCVE-2026-55483—22.8%
——7Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php strips superuser permission but does not strip admin permission. The created account can obtain administrative privileges. This issue is fixed in version 8.6.0.1dCVE-2022-22622—22.8%
——7——CVE-2025-46425—22.8%
——7——CVE-2025-12429—22.8%
——7——CVE-2026-48943—22.8%
——7——CVE-2025-31724—22.8%
——7——CVE-2023-25862—22.8%
——7——CVE-2023-42577—22.8%
——7——CVE-2020-24451—22.8%
——7——CVE-2023-45737—22.8%
——7——CVE-2024-9072—22.8%
——7——CVE-2026-57338.8 HIG22.8%
——7Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.58dCVE-2024-10186—22.8%
——7——CVE-2024-12566—22.8%
——7——CVE-2024-6668—22.8%
——7——CVE-2026-54202—22.8%
——7Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the
archive creation functionality. Because the archive path is
user-controlled and insufficiently validated, an attacker can manipulate
the input to traverse directories. This allows the creation of folders
in arbitrary locations, including sensitive directories such as
C:\Windows or for different users. This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.3dCVE-2025-8901—22.8%
——7——