Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,374
- High9,659
- Medium5,457
- Low529
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-68837—15.9%
——5——CVE-2026-197266.5 MED15.9%
——5The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin before 4.0.7's own interface denies them, and to retrieve every chart's configuration in a single request. The disclosed configuration can include the credentials of a remote data source a chart reads from.3dCVE-2025-23044—15.9%
——5——CVE-2026-12302—15.9%
——5——CVE-2014-5323—15.9%
——5——CVE-2025-1748—15.9%
——5——CVE-2020-35534—15.9%
——5——CVE-2022-4936—15.9%
——5——CVE-2025-43732—15.9%
——5——CVE-2021-47877—15.9%
——5——CVE-2026-762576.5 MED15.9%
——5In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list storage passwords but does not hold Splunk Secure Gateway administration privileges could access Mobile Device Management signing secrets that compromise all affected mobile-device enrollment trust through Splunk Secure Gateway. The vulnerability is possible because Splunk Secure Gateway Representational State Transfer (REST) API endpoints for deployment bundle, Security Assertion Markup Language setup, and companion app workflows do not require Splunk Secure Gateway administration privileges before processing requests.9dCVE-2021-46950—15.9%
——5——CVE-2025-713908.8 HIG15.9%
——5SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>) with a hostname that resolves to a denied IP address, causing the server to issue the request anyway and return the response. This bypasses network access controls, allowing access to restricted internal endpoints and potentially retrieving or altering sensitive information and credentials, depending on the deployment.16dCVE-2023-32408—15.9%
——5——CVE-2006-6653—15.9%
——5——CVE-2025-32496—15.9%
——5——CVE-2026-131698.1 HIG15.9%
——5The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators.10dCVE-2026-544188.1 HIG15.9%
——5Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher).18hCVE-2026-2306—15.9%
——5——CVE-2025-54705—15.9%
——5——CVE-2025-0667—15.9%
——5——CVE-2025-55135—15.9%
——5——CVE-2025-1512—15.9%
——5——CVE-2025-54467—15.9%
——5——CVE-2024-12189—15.9%
——5——CVE-2023-26000—15.9%
——5——CVE-2026-27988.8 HIG15.9%
——5Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.45dCVE-2023-7269—15.9%
——5——CVE-2026-115203.5 LOW15.9%
——5A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Multiple parameters might be affected.37dCVE-2025-20273—15.9%
——5——CVE-2026-33335—15.9%
——5——CVE-2009-2752—15.9%
——5——CVE-2025-9183—15.9%
——5——CVE-2025-30528—15.9%
——5——CVE-2025-13584—15.9%
——5——CVE-2025-2042—15.9%
——5——CVE-2026-138406.5 MED15.9%
——5Insufficient policy enforcement in Canvas in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)58dCVE-2026-94853.5 LOW15.9%
——5A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.37dCVE-2020-12035—15.9%
——5——CVE-2022-50751—15.9%
——5——