Vulnerabilities exploitable today
369,220in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,184
- High7,856
- Medium5,748
- Low554
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-92739.3 CRI19.7%
——6The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/forms.php: wp_redirect( esc_url( $_POST['rc_redirect'] ) . ... ) at line 243, and add_query_arg( array( 'key' => $key, 'login' => ... ), $_POST['rc_redirect'] ) inside rc_send_password_reset_email() at line 306. The nonce required to reach the handler is broadcast by the public [login_form] shortcode at line 207 to any anonymous visitor. This makes it possible for unauthenticated attackers to issue a password-reset request for any account (including administrators) whose reset email body points the victim at an attacker-controlled host carrying a valid reset key/login. When the victim clicks the link, the reset key leaks to the attacker, who can replay it against the legitimate site to complete account takeover.24dCVE-2025-20712—19.7%
——6——CVE-2025-15199—19.7%
——6——CVE-2025-23494—19.7%
——6——CVE-2025-58240—19.7%
——6——CVE-2026-2105—19.7%
——6——CVE-2018-7910—19.7%
——6——CVE-2021-47956—19.7%
——6——CVE-2025-2246—19.7%
——6——CVE-2025-53454—19.7%
——6——CVE-2024-36613—19.7%
——6——CVE-2024-41785—19.7%
——6——CVE-2025-22760—19.7%
——6——CVE-2025-32116—19.7%
——6——CVE-2023-52490—19.7%
——6——CVE-2026-9053—19.7%
——6Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file path, and then conceal this form element.44dCVE-2026-89896.8 MED19.7%
——6Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.23dCVE-2026-28871—19.7%
——6——CVE-2026-2745—19.7%
——6——CVE-2024-23294—19.7%
——6——CVE-2025-23648—19.7%
——6——CVE-2025-20908—19.7%
——6——CVE-2025-23473—19.7%
——6——CVE-2011-1056—19.7%
——6——CVE-2020-37242—19.7%
——6——CVE-2026-853888.1 HIG19.7%
——6Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for CVE-2026-25947.2dCVE-2026-704928.7 HIG19.7%
——6Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. The catch branch fell back to inserting the original math source into the page as HTML through {@html} rather than as text, so script in the message runs in the browser of whoever views it, including shared chats and channels. The viewer's session token in localStorage can be stolen, and an administrator viewer can have their account taken over. This issue is fixed in 0.11.0.31dCVE-2024-2007—19.7%
——6——CVE-2024-26928—19.7%
——6——CVE-2025-64748—19.7%
——6——CVE-2026-843518.3 HIG19.7%
——6Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)2dCVE-2025-10137—19.7%
——6——CVE-2025-23517—19.7%
——6——CVE-2026-32269—19.7%
——6——CVE-2026-789843.4 LOW19.7%
——6Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)5dCVE-2025-58239—19.7%
——6——CVE-2024-44201—19.7%
——6——CVE-2026-226818.5 HIG19.7%
——6OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918, link-local, or cloud metadata addresses, then read back responses through normal content APIs to enumerate and interact with internal services.15dCVE-2025-26991—19.7%
——6——CVE-2025-23647—19.7%
——6——