Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,243
- High8,317
- Medium6,349
- Low609
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-14487.8 HIG22.6%
——7A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is running in multi-instance mode. This vulnerability is due to insufficient validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input to the affected command. A successful exploit could allow the attacker to execute commands on the underlying operating system with root privileges.30dCVE-2026-53576.4 MED22.6%
——7The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. The sid parameter is extracted without sanitization in the members() function and stored via update_post_meta(), then echoed directly into an HTML id attribute in the members.php template without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page.48dCVE-2019-18373—22.6%
——7——CVE-2026-1841—22.6%
——7——CVE-2026-524756.1 MED22.6%
——7Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file50dCVE-2007-2063—22.6%
——7——CVE-2025-14190—22.6%
——7——CVE-2024-26574—22.6%
——7——CVE-2016-11032—22.6%
——7——CVE-2024-6432—22.6%
——7——CVE-2025-59376—22.6%
——7——CVE-2005-1286—22.6%
——7——CVE-2023-41523—22.6%
——7——CVE-2025-0897—22.6%
——7——CVE-2024-42459—22.6%
——7——CVE-2026-159935.3 MED22.6%
——7The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause in all versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires that a form is configured with a DB-backed dynamic choice field whose WHERE template references the {username} placeholder, and the attacker must first set their own display_name to a SQL payload via the standard WordPress profile edit screen before triggering the fm_reload_input AJAX endpoint.21dCVE-2024-47780—22.6%
——7——CVE-2007-1716—22.6%
——7——CVE-2023-4420—22.6%
——7——CVE-2009-1981—22.6%
——7——CVE-2025-14091—22.6%
——7——CVE-2025-7822—22.6%
——7——CVE-2005-1720—22.6%
——7——CVE-2025-13061—22.6%
——7——CVE-2025-0797—22.6%
——7——CVE-2025-13439—22.6%
——7——CVE-2020-0196—22.6%
——7——CVE-2008-1598—22.6%
——7——CVE-2008-3147—22.6%
——7——CVE-2023-31410—22.6%
——7——CVE-2025-8917—22.6%
——7——CVE-2024-13563—22.6%
——7——CVE-2025-62788—22.6%
——7——CVE-2024-47346—22.6%
——7——CVE-2023-23855—22.6%
——7——CVE-2023-41531—22.6%
——7——CVE-2025-12248—22.6%
——7——CVE-2023-41522—22.6%
——7——CVE-2024-47339—22.6%
——7——CVE-2026-59881—22.6%
——7AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2.42d