Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,311
- High9,414
- Medium5,381
- Low529
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-0727—18.2%
——5——CVE-2023-25518—18.2%
——5——CVE-2025-27265—18.2%
——5——CVE-2026-1104—18.2%
——5——CVE-2025-27305—18.2%
——5——CVE-2022-48423—18.2%
——5——CVE-2024-39348—18.2%
——5——CVE-2014-6847—18.2%
——5——CVE-2014-6846—18.2%
——5——CVE-2014-6848—18.2%
——5——CVE-2014-6874—18.2%
——5——CVE-2026-673227.5 HIG18.2%
——5GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or ${NAME} tokens that are expanded to the values of the hosting process's environment variables (e.g., AWS_SECRET_ACCESS_KEY or GITHUB_TOKEN). The resulting URL, now containing the secret, is transmitted over the network to an attacker-controlled host during the clone attempt, disclosing the secret.1dCVE-2026-574077.2 HIG18.2%
——5Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2.50dCVE-2025-11678—18.2%
——5——CVE-2023-37012—18.2%
——5——CVE-2026-654996.5 MED18.2%
——5Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.40dCVE-2026-161457.2 HIG18.2%
——5The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The stored payload is written by any unauthenticated admin-ajax.php request whose action value matches an entry in the plugin's explicit-actions list, which is auto-populated for common form builders at activation and requires no authentication gate to reach the save path.12dCVE-2014-6872—18.2%
——5——CVE-2022-42946—18.2%
——5——CVE-2025-41004—18.2%
——5——CVE-2026-655167.2 HIG18.2%
——5Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.40dCVE-2025-13282—18.2%
——5——CVE-2024-21161—18.2%
——5——CVE-2014-7577—18.2%
——5——CVE-2026-30570—18.2%
——5——CVE-2026-24487—18.2%
——5——CVE-2024-7380—18.2%
——5——CVE-2014-7576—18.2%
——5——CVE-2026-55786.3 MED18.2%
——5A vulnerability was found in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /OnlineClassroom/addassessment.php of the component Parameter Handler. Performing a manipulation of the argument deleteid results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.39dCVE-2025-22479—18.2%
——5——CVE-2024-42380—18.2%
——5——CVE-2026-736128.1 HIG18.2%
——5File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based isolation for confidentiality and integrity.19dCVE-2022-28198—18.2%
——5——CVE-2026-492347.5 HIG18.2%
——5When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes.
This only affects users who allow API access from untrusted networks.41dCVE-2026-30571—18.2%
——5——CVE-2026-52701—18.2%
——5——CVE-2025-27280—18.2%
——5——CVE-2026-573487.2 HIG18.2%
——5Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.61dCVE-2014-6844—18.2%
——5——CVE-2025-9658—18.2%
——5——