Vulnerabilities exploitable today
363,850in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,846
- High11,709
- Medium7,103
- Low667
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-8694—12.9%
——4——CVE-2026-187795.3 MED12.9%
——4The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.2dCVE-2026-187775.3 MED12.9%
——4The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.2dCVE-2026-71205.3 MED12.9%
——4@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2.24dCVE-2024-38566—12.9%
——4——CVE-2025-13068—12.9%
——4——CVE-2026-57630—12.9%
——4——CVE-2020-37105—12.9%
——4——CVE-2025-12075—12.9%
——4——CVE-2025-49390—12.9%
——4——CVE-2025-59006—12.9%
——4——CVE-2026-100037.5 HIG12.9%
——4Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)31dCVE-2025-22726—12.9%
——4——CVE-2026-100097.5 HIG12.9%
——4Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)31dCVE-2025-21751—12.9%
——4——CVE-2023-52698—12.9%
——4——CVE-2024-31238—12.9%
——4——CVE-2024-31573—12.9%
——4——CVE-2024-12220—12.9%
——4——CVE-2025-52764—12.9%
——4——CVE-2025-24116—12.9%
——4——CVE-2025-53239—12.9%
——4——CVE-2024-35902—12.9%
——4——CVE-2024-410197.8 HIG12.9%
——4In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Validate ff offset
This adds sanity checks for ff offset. There is a check
on rt->first_free at first, but walking through by ff
without any check. If the second ff is a large offset.
We may encounter an out-of-bound read.17dCVE-2026-28433—12.9%
——4——CVE-2026-143175.3 MED12.9%
——4The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled.21dCVE-2023-21969—12.9%
——4——CVE-2024-46715—12.9%
——4——CVE-2022-31622—12.9%
——4——CVE-2025-14688—12.9%
——4——CVE-2026-31413—12.9%
——4——CVE-2026-395435.3 MED12.9%
——4Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.21.4.28dCVE-2015-8955—12.9%
——4——CVE-2023-51486—12.9%
——4——CVE-2023-48645—12.9%
——4——CVE-2025-9343—12.9%
——4——CVE-2026-762556.4 MED12.9%
——4In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the "admin" or "power" Splunk roles could trick another user into running arbitrary Search Processing Language (SPL) commands through the Data Model Editor using the permissions of the affected user. The commands could access all relevant data available to the affected user and affect system integrity. The vulnerability is possible because Splunk Web does not apply SPL safeguards for risky commands when the Data Model Editor runs the base search for auto-extracted fields. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who does not hold the "admin" or "power" Splunk roles should not be able to exploit the vulnerability at will. For more information see SPL safeguards for risky commands (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/best-practices-for-splunk-platform-security/spl-safeguards-for-risky-commands) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.17hCVE-2025-66123—12.9%
——4——CVE-2026-57323—12.9%
——4——CVE-2026-45007—12.9%
——4——