Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,394
- High10,137
- Medium5,050
- Low465
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-46820—13.7%
——4——CVE-2021-27483—13.7%
——4——CVE-2025-45662—13.7%
——4——CVE-2026-663996.5 MED13.7%
——4phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required rights. Attackers can add themselves to pre-existing groups holding user-management rights and immediately inherit those permissions to modify or delete user accounts.28dCVE-2026-137284.4 MED13.7%
——4In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources.
This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.15dCVE-2022-28619—13.7%
——4——CVE-2026-40889—13.7%
——4——CVE-2026-539926.1 MED13.7%
——4ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in the start_date and end_date GET parameters, which are echoed unescaped into HTML attribute values. Attackers can craft a malicious URL that, when followed by an authenticated victim with edit_settings permissions, executes injected scripts in the application origin to steal session cookies or perform unauthorized actions including user management, file management, and application settings changes.20dCVE-2025-2276—13.7%
——4——CVE-2023-42560—13.7%
——4——CVE-2026-40113—13.7%
——4——CVE-2026-0160—13.7%
——4——CVE-2025-64030—13.7%
——4——CVE-2025-53494—13.7%
——4——CVE-2026-354467.7 HIG13.7%
——4LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 and 28.0.1, an incorrect order of operations in the FilesDownloadHandler could result in an attacker escaping the intended download directories. This vulnerability is fixed in 27.0.3 and 28.0.1.32dCVE-2026-0151—13.7%
——4——CVE-2022-49961—13.7%
——4——CVE-2026-38568—13.7%
——4——CVE-2021-25403—13.7%
——4——CVE-2018-5883—13.7%
——4——CVE-2025-46311—13.7%
——4——CVE-2025-55273—13.7%
——4——CVE-2023-4251—13.7%
——4——CVE-2024-52882—13.7%
——4——CVE-2025-13034—13.7%
——4——CVE-2025-57665—13.7%
——4——CVE-2025-3997—13.7%
——4——CVE-2026-42501—13.7%
——4——CVE-2026-160656.5 MED13.7%
——4The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.19dCVE-2026-178276.1 MED13.7%
——4Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)22dCVE-2026-53407—13.7%
——4——CVE-2018-11845—13.7%
——4——CVE-2026-2288—13.6%
——4——CVE-2026-26170—13.6%
——4——CVE-2021-46954—13.6%
——4——CVE-2025-4566—13.6%
——4——CVE-2023-52528—13.6%
——4——CVE-2023-52875—13.6%
——4——CVE-2026-616966.3 MED13.6%
——4Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c, a malicious value submitted through feedback_message[message] is stored without sanitization and rendered in app/views/admin/feedback_messages/_feedback_message.html.erb through raw(feedback_message.message) when offender_id is present. Viewing the abuse report executes arbitrary JavaScript in an administrator's browser and may expose sensitive in-page data, abuse CSRF tokens, or perform administrative actions in the victim's session. The public FeedbackMessagesController accepts the report without authorization and previously permitted a submitted offender_id, making the vulnerable rendering path reachable by an unauthenticated attacker. This issue is fixed in commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c7dCVE-2024-40807—13.6%
——4——