Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1886—15.3%
——5——CVE-2024-45857—15.3%
——5——CVE-2024-35635—15.3%
——5——CVE-2020-37240—15.3%
——5——CVE-2026-27777—15.3%
——5——CVE-2020-37238—15.3%
——5——CVE-2025-7969—15.3%
——5——CVE-2026-3528—15.3%
——5——CVE-2025-67559—15.3%
——5——CVE-2026-34247—15.3%
——5——CVE-2024-56601—15.3%
——5——CVE-2026-2176—15.3%
——5——CVE-2026-40806.4 MED15.3%
——5The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the ectp_add_to_cart() function uses sanitize_text_field() on shortcode attributes like 'itemid', 'product_name', 'product_desc', 'product_qty', and 'price' before inserting them into double-quoted HTML attributes. While sanitize_text_field() strips HTML tags, it does not escape double quote characters, allowing an attacker to break out of the HTML attribute context and inject arbitrary event handlers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.36dCVE-2025-59160—15.3%
——5——CVE-2025-30732—15.3%
——5——CVE-2026-470813.1 LOW15.3%
——5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed.41dCVE-2026-33517—15.3%
——5——CVE-2026-80857.3 HIG15.3%
——5A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.44dCVE-2025-54206—15.3%
——5——CVE-2026-184006.4 MED15.3%
——5The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The ml-slider custom post type is registered without custom capability restrictions and the ml-slider_settings meta key is unprotected, allowing Author-level users to set the malicious delay value via XML-RPC custom_fields when creating an ml-slider post.15dCVE-2024-43228—15.3%
——5——CVE-2026-44521—15.3%
——5——CVE-2025-21428—15.3%
——5——CVE-2026-40410—15.3%
——5——CVE-2024-54213—15.3%
——5——CVE-2025-15150—15.3%
——5——CVE-2024-1456—15.3%
——5——CVE-2025-55285—15.3%
——5——CVE-2026-792188.3 HIG15.3%
——5Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)23hCVE-2026-5340—15.3%
——5——CVE-2026-732905.3 MED15.3%
——5RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant falls back to an s3:ListBucket check and returns before the policy_allowed path applies deny_anonymous_table_data_plane_if_needed and RestrictPublicBuckets, so a bucket that permits anonymous listing can continue exposing version listings after an operator enables the public-access control. The bypass affects GET /<bucket>?versions= and can disclose object version metadata even though equivalent GetObject requests are denied. This issue is fixed in version 1.0.0-beta.12.15dCVE-2026-3529—15.3%
——5——CVE-2025-48276—15.3%
——5——CVE-2020-37235—15.3%
——5——CVE-2023-46250—15.3%
——5——CVE-2022-31601—15.3%
——5——CVE-2025-13515—15.3%
——5——CVE-2025-24280—15.3%
——5——CVE-2024-56642—15.3%
——5——CVE-2024-38876—15.3%
——5——