Vulnerabilities exploitable today
360,835in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,641
- High11,455
- Medium7,085
- Low644
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-55629—12.1%
——4——CVE-2026-396435.3 MED12.1%
——4Missing Authorization vulnerability in Payment Plugins Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Plugins for PayPal WooCommerce: from n/a through <= 2.0.13.25dCVE-2026-577658.5 HIG12.1%
——4Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.47dCVE-2026-25415—12.1%
——4——CVE-2026-38939—12.1%
——4——CVE-2026-24577—12.1%
——4——CVE-2026-3770—12.1%
——4——CVE-2025-12109—12.1%
——4——CVE-2026-41182—12.1%
——4——CVE-2026-32382—12.1%
——4——CVE-2026-41313—12.1%
——4——CVE-2026-32347—12.1%
——4——CVE-2026-53949—12.1%
——4——CVE-2026-647578.8 HIG12.1%
——4A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.12hCVE-2025-33226—12.1%
——4——CVE-2026-395885.3 MED12.1%
——4Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Lite: from n/a through <= 5.13.25dCVE-2026-24568—12.1%
——4——CVE-2024-57838—12.1%
——4——CVE-2026-734015.3 MED12.1%
——4Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.4dCVE-2026-32376—12.1%
——4——CVE-2026-25440—12.1%
——4——CVE-2022-41850—12.1%
——4——CVE-2026-734035.3 MED12.1%
——4Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.4dCVE-2026-13495—12.1%
——4——CVE-2026-396635.3 MED12.1%
——4Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.5.25dCVE-2026-396565.3 MED12.1%
——4Missing Authorization vulnerability in Razorpay Razorpay for WooCommerce woo-razorpay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay for WooCommerce: from n/a through <= 4.8.2.25dCVE-2021-36795—12.1%
——4——CVE-2025-26561—12.1%
——4——CVE-2025-14797—12.1%
——4——CVE-2022-31071—12.1%
——4——CVE-2024-43338—12.1%
——4——CVE-2024-43902—12.1%
——4——CVE-2025-27260—12.1%
——4——CVE-2026-25584—12.1%
——4——CVE-2026-24116—12.1%
——4——CVE-2026-396025.3 MED12.1%
——4Missing Authorization vulnerability in Rustaurius Order Tracking order-tracking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Tracking: from n/a through <= 3.4.3.25dCVE-2026-32425—12.1%
——4——CVE-2025-40332—12.1%
——4——CVE-2024-52522—12.1%
——4——CVE-2026-25364—12.1%
——4——