Vulnerabilities exploitable today
369,392in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,099
- High7,540
- Medium5,594
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-131756.5 MED20.9%
——6The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users.19dCVE-2026-285677.5 HIG20.9%
——6Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.18dCVE-2026-3321—20.9%
——6——CVE-2022-29915—20.9%
——6——CVE-2026-22351—20.9%
——6——CVE-2025-14277—20.9%
——6——CVE-2026-27803—20.8%
——6——CVE-2024-9473—20.9%
——6——CVE-2026-255624.3 MED20.9%
——6WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing attachment metadata to unauthorized users.55dCVE-2026-27374—20.9%
——6——CVE-2025-9168—20.9%
——6——CVE-2004-0481—20.9%
——6——CVE-2023-22316—20.9%
——6——CVE-2005-2864—20.9%
——6——CVE-2025-59133—20.9%
——6——CVE-2026-784387.2 HIG20.9%
——6The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the "Lazy Load Images" feature with "Process background images" to be enabled, and the malicious comment to be approved by a moderator before execution is triggered.2dCVE-2026-53471—20.9%
——6——CVE-2026-12007—20.9%
——6——CVE-2026-40767—20.9%
——6——CVE-2026-177345.4 MED20.9%
——6Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)28dCVE-2025-59416—20.9%
——6——CVE-2026-402936.5 MED20.9%
——6OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint. The /playground endpoint is enabled by default and does not require authentication. It is intended for local development and debugging and is not designed to be exposed to production environments. Only those who run OpenFGA with `--authn-method` preshared, with the playground enabled, and with the playground endpoint accessible beyond localhost or trusted networks are vulnerable. To remediate the issue, users should upgrade to OpenFGA v1.14.0, or disable the playground by running `./openfga run --playground-enabled=false.`14dCVE-2025-52953—20.9%
——6——CVE-2025-57213—20.9%
——6——CVE-2023-47586—20.9%
——6——CVE-2026-595058.6 HIG20.9%
——6: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.10dCVE-2004-1023—20.9%
——6——CVE-2023-5866—20.9%
——6——CVE-2023-21733—20.9%
——6——CVE-2026-30910—20.9%
——6——CVE-2026-710387.5 HIG20.9%
——6Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).18dCVE-1999-0476—20.9%
——6——CVE-2025-9169—20.9%
——6——CVE-2023-45053—20.9%
——6——CVE-2026-500919.1 CRI20.9%
——6Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical).60dCVE-2026-619847.5 HIG20.9%
——6Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.24dCVE-2026-39513—20.9%
——6——CVE-2026-42850—20.9%
——6——CVE-2025-5944—20.9%
——6——CVE-2026-97657.1 HIG20.9%
——6Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue.
Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions.
Broken access control can allow attackers to:
Access resources only accessible to certain users, thus allowing unauthorized access to data
Perform operations on behalf of other users, leading to account takeovers in the worst cases
Attempt privilege escalation
Attempt to take over an account39d