Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,365
- High10,105
- Medium4,998
- Low469
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-3440—14.9%
——4——CVE-2025-0663—14.9%
——4——CVE-2026-33215—14.9%
——4——CVE-2020-14328—14.9%
——4——CVE-2022-38378—14.9%
——4——CVE-2025-7821—14.9%
——4——CVE-2025-35034—14.9%
——4——CVE-2026-714345.3 MED14.9%
——4Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could upload file types an administrator had intended to disallow through a form's assets or files field, and for assets fields, files could be stored on a public, web-accessible disk, though the application's global upload allowlist still blocked executable types such as .php and .html. This issue is fixed in versions 5.74.3 and 6.24.2.20dCVE-2026-547175.4 MED14.9%
——4Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is fixed in 6.2.1.20dCVE-2025-40556—14.9%
——4——CVE-2025-43553—14.9%
——4——CVE-2025-32801—14.9%
——4——CVE-2026-395715.3 MED14.9%
——4Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themefic Instantio instantio allows Retrieve Embedded Sensitive Data.This issue affects Instantio: from n/a through <= 3.3.30.34dCVE-2026-631366.5 MED14.9%
——4Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.20dCVE-2026-395425.3 MED14.9%
——4Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Doofinder for WooCommerce: from n/a through <= 2.10.13.34dCVE-2022-24913—14.9%
——4——CVE-2024-358307.8 HIG14.9%
——4In the Linux kernel, the following vulnerability has been resolved:
media: tc358743: register v4l2 async device only after successful setup
Ensure the device has been setup correctly before registering the v4l2
async device, thus allowing userspace to access.23dCVE-2024-55016—14.9%
——4——CVE-2024-54011—14.9%
——4——CVE-2026-130897.5 HIG14.9%
——4OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify.
When the caller does not pin an algorithm, OIDC::Lite::Model::IDToken::verify sets $self->alg($self->header->{alg}) from the token's own header and then calls decode_jwt(token, key, 1, [$self->alg]), handing JSON::WebToken an accepted-algorithm allowlist taken from the untrusted token. A token with alg=none yields ['none'], so decode_jwt returns the claims with no signature check, and a token with alg=HS256 is verified with the RP's RSA public key as the HMAC secret (RS to HS confusion).
The ID Token is the OpenID Connect authentication assertion delivered to the Relying Party. Any caller that verifies an ID Token through the unpinned load(token)->verify path, or load(token, key) with only the key pinned, accepts a forged token carrying attacker-chosen claims such as sub and is authenticated as any user. Passing an explicit algorithm so $self->alg is already set bypasses the header-derived allowlist and is not affected.
Note that the latest version uploaded to CPAN is 0.10. Later versions are available in the git repository.31dCVE-2023-53876—14.9%
——4——CVE-2026-42875—14.9%
——4——CVE-2026-749019.8 CRI14.9%
——4openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.10dCVE-2024-44657—14.9%
——4——CVE-2025-31988—14.9%
——4——CVE-2026-395865.3 MED14.9%
——4Insertion of Sensitive Information Into Sent Data vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through <= 4.1132.34dCVE-2017-9645—14.9%
——4——CVE-2026-394735.3 MED14.9%
——4Insertion of Sensitive Information Into Sent Data vulnerability in Pär Thernström Simple History simple-history allows Retrieve Embedded Sensitive Data.This issue affects Simple History: from n/a through <= 5.24.0.34dCVE-2023-6094—14.9%
——4——CVE-2026-40158—14.9%
——4——CVE-2024-44632—14.9%
——4——CVE-2026-631446.5 MED14.9%
——4Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation component, causing a fatal error that terminates the affected node. In single-node deployments, this results in complete service outage; in multi-node clusters, it causes repeated node restarts and sustained availability degradation.24dCVE-2026-58103.5 LOW14.9%
——4A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argument ID causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used.35dCVE-2025-57821—14.9%
——4——CVE-2026-33385—14.9%
——4A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks.
The vendor states that this administration panel already allows for significant modification capabilities. The SQL injection vulnerability primarily enables bypassing front-end validation controls and potential database destruction. Given the trust model in which this application is designed to be administered, remediation of this issue was not deemed necessary by the vendor.
This vulnerability has been found in version 6.8, but other versions might also be vulnerable.28dCVE-2026-740085.3 MED14.9%
——4Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.7dCVE-2024-44652—14.9%
——4——CVE-2026-32405—14.9%
——4——CVE-2024-44654—14.9%
——4——CVE-2026-21870—14.9%
——4——