Vulnerabilities exploitable today
369,690in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,132
- High7,666
- Medium5,751
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-8872—21.7%
——7——CVE-2026-107717.3 HIG21.7%
——7A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in server-side request forgery. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.48dCVE-2026-577215.3 MED21.7%
——7Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects ApplyOnline: from n/a through 2.6.7.6.69dCVE-2024-7654—21.7%
——7——CVE-2023-40384—21.7%
——7——CVE-2026-40781—21.6%
——7——CVE-2021-3459—21.7%
——7——CVE-2024-7544—21.7%
——7——CVE-2026-655255.3 MED21.7%
——7Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.47dCVE-2026-41888—21.7%
——7——CVE-2023-27442—21.7%
——7——CVE-2022-490547.1 HIG21.7%
——7In the Linux kernel, the following vulnerability has been resolved:
Drivers: hv: vmbus: Deactivate sysctl_record_panic_msg by default in isolated guests
hv_panic_page might contain guest-sensitive information, do not dump it
over to Hyper-V by default in isolated guests.
While at it, update some comments in hyperv_{panic,die}_event().35dCVE-2024-43125—21.7%
——7——CVE-2023-47670—21.7%
——7——CVE-2023-41129—21.7%
——7——CVE-2023-47667—21.7%
——7——CVE-2020-0562—21.7%
——7——CVE-2024-42325—21.7%
——7——CVE-2025-42970—21.7%
——7——CVE-2024-33627—21.7%
——7——CVE-2025-66837—21.7%
——7——CVE-2026-57660—21.7%
——7——CVE-2024-40778—21.7%
——7——CVE-2026-274185.3 MED21.7%
——7Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.47dCVE-2026-7158—21.7%
——7——CVE-2026-7733—21.7%
——7——CVE-2025-22291—21.7%
——7——CVE-2020-0547—21.7%
——7——CVE-2026-654535.3 MED21.7%
——7Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.47dCVE-2026-56706—21.7%
——7——CVE-2024-11159—21.7%
——7——CVE-2026-577785.3 MED21.7%
——7Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.57dCVE-2023-47519—21.7%
——7——CVE-2023-47556—21.7%
——7——CVE-2023-43782—21.7%
——7——CVE-2025-64636—21.7%
——7——CVE-2025-31036—21.7%
——7——CVE-2026-4200—21.7%
——7——CVE-2026-619855.3 MED21.7%
——7Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7.57dCVE-2026-5309—21.7%
——7——