Vulnerabilities exploitable today
366,910in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,352
- Medium5,308
- Low511
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-254244.3 MED16.7%
——5Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.38dCVE-2024-35740—16.7%
——5——CVE-2026-193557.3 HIG16.7%
——5A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.17dCVE-2026-39325—16.7%
——5——CVE-2024-38785—16.7%
——5——CVE-2024-35676—16.7%
——5——CVE-2025-9093—16.7%
——5——CVE-2023-36671—16.7%
——5——CVE-2022-21153—16.7%
——5——CVE-2025-32816—16.7%
——5——CVE-2024-23848—16.7%
——5——CVE-2026-576854.3 MED16.7%
——5Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.59dCVE-2026-34244—16.7%
——5——CVE-2025-68551—16.7%
——5——CVE-2024-38430—16.7%
——5——CVE-2025-62655—16.7%
——5——CVE-2025-46256—16.7%
——5——CVE-2024-34566—16.7%
——5——CVE-2023-47778—16.7%
——5——CVE-2024-43992—16.7%
——5——CVE-2026-411234.3 MED16.7%
——5Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.52dCVE-2026-274234.3 MED16.7%
——5Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.38dCVE-2020-1819—16.7%
——5——CVE-2021-47781—16.7%
——5——CVE-2020-1822—16.7%
——5——CVE-2026-8083—16.7%
——5——CVE-2026-26196—16.7%
——5——CVE-2026-7130—16.7%
——5——CVE-2025-68040—16.7%
——5——CVE-2026-6004—16.7%
——5——CVE-2026-7228—16.7%
——5——CVE-2020-1821—16.7%
——5——CVE-2021-20349—16.7%
——5——CVE-2026-8785—16.7%
——5——CVE-2026-742506.3 MED16.7%
——5In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.13dCVE-2025-11082—16.7%
——5——CVE-2026-4288—16.7%
——5——CVE-2026-57648—16.7%
——5——CVE-2026-8130—16.7%
——5——CVE-2024-35082—16.7%
——5——