Vulnerabilities exploitable today
369,690in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,132
- High7,666
- Medium5,751
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-4588—21.7%
——7——CVE-2025-660765.3 MED21.7%
——7Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.68dCVE-2026-114627.3 HIG21.7%
——7A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authorization. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named 6719e0fc690ea0a998452092862e0f0a17c65968. It is suggested to install a patch to address this issue.47dCVE-2026-102877.3 HIG21.7%
——7A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.48dCVE-2026-6781—21.7%
——7——CVE-2025-31038—21.7%
——7——CVE-2025-37872—21.7%
——7——CVE-2026-466568.8 HIG21.7%
——7Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain full unauthorized access to the system. Version 3.22.0 fixes the issue.47dCVE-2022-31610—21.7%
——7——CVE-2026-577825.3 MED21.7%
——7Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.57dCVE-2025-21124—21.7%
——7——CVE-2026-577605.3 MED21.7%
——7Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Sendcloud Shipping: from n/a through 1.0.29.68dCVE-2019-11167—21.7%
——7——CVE-2019-20729—21.7%
——7——CVE-2026-567796.4 MED21.7%
——7MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by supplying unvalidated downloadCallbackUrl and download_url parameters. Attackers with default workspace USER role can exploit this to access internal network services by providing malicious URLs to the ToolSerializer endpoints.56dCVE-2023-47672—21.7%
——7——CVE-2026-7065—21.7%
——7——CVE-2024-7545—21.7%
——7——CVE-2020-0560—21.7%
——7——CVE-2025-2131—21.6%
——6——CVE-1999-0694—21.6%
——6——CVE-2019-18684—21.6%
——6——CVE-2020-10782—21.6%
——6——CVE-2018-20943—21.6%
——6——CVE-2021-1839—21.6%
——6——CVE-2023-41232—21.6%
——6——CVE-2026-595487.5 HIG21.6%
——6Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.43dCVE-2026-157698.3 HIG21.6%
——6Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)55dCVE-2020-15247—21.6%
——6——CVE-2023-23522—21.6%
——6——CVE-2024-40635—21.6%
——6——CVE-2025-68857—21.6%
——6——CVE-2026-2979—21.6%
——6——CVE-2022-25641—21.6%
——6——CVE-2026-97994.6 MED21.6%
——6A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of that type within the same resource server, even if they do not have a ticket for those specific resources. This vulnerability requires the resource server to be configured in PERMISSIVE policy enforcement mode and affects typed resources with ownerManagedAccess enabled, where no explicit policy protects the resource type. The primary consequence is unauthorized information disclosure or modification of resources.69dCVE-2023-45227—21.6%
——6——CVE-2026-544817.5 HIG21.6%
——6Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)13dCVE-2026-177499.6 CRI21.6%
——6Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Medium)29dCVE-2026-95944.4 MED21.6%
——6The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the attacker to hold the custom wpgmp_manage_location capability, which is granted to administrators by default but can be assigned to lower-privileged roles via the plugin's Permissions screen.47dCVE-2026-88534.4 MED21.6%
——6The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the memo value is stored via update_post_meta() rather than wp_insert_post(), WordPress's built-in kses and unfiltered_html protections do not apply, allowing attackers to break out of the textarea element via injected closing tags regardless of role-based content filtering.47d