Vulnerabilities exploitable today
360,723in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,507
- High11,060
- Medium7,099
- Low642
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-150058.8 HIG11.7%
——4The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses path validation and is passed directly to the include sink in execTemplate() via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.31dCVE-2025-41036—11.7%
——4——CVE-2026-161044.3 MED11.7%
——4A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.10dCVE-2025-43287—11.7%
——4——CVE-2023-38593—11.7%
——4——CVE-2022-38764—11.7%
——4——CVE-2023-5182—11.7%
——4——CVE-2025-68227—11.7%
——4——CVE-2024-47055—11.7%
——4——CVE-2025-42901—11.7%
——4——CVE-2026-33312—11.7%
——4——CVE-2020-3646—11.7%
——4——CVE-2026-45011—11.7%
——4——CVE-2026-31352—11.7%
——4——CVE-2021-26579—11.7%
——4——CVE-2025-43303—11.7%
——4——CVE-2025-6652—11.6%
——3——CVE-2021-29576—11.6%
——3——CVE-2024-40915—11.6%
——3——CVE-2026-648286.1 MED11.6%
——3Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field without sanitization. Attackers can craft malicious payloads in customer order placement that execute in the admin's browser session when viewing order details, enabling session token theft or unauthorized administrative actions.9dCVE-2025-6649—11.6%
——3——CVE-2021-29583—11.6%
——3——CVE-2025-54259—11.6%
——3——CVE-2021-29512—11.6%
——3——CVE-2022-30984—11.6%
——3——CVE-2022-3928—11.6%
——3——CVE-2025-63053—11.6%
——3——CVE-2025-10305—11.6%
——3——CVE-2024-21119—11.6%
——3——CVE-2026-33740—11.6%
——3——CVE-2026-347365.3 MED11.6%
——3Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before the ulmo release, an unauthenticated attacker can fully bypass the email verification process by combining two issues: the OAuth2 password grant issuing tokens to inactive users (documented behavior) and the activation_key being exposed in the REST API response at /api/user/v1/accounts/. This issue has been patched in the ulmo release.23dCVE-2023-51778—11.6%
——3——CVE-2026-27605—11.6%
——3——CVE-2025-54260—11.6%
——3——CVE-2025-63002—11.6%
——3——CVE-2025-36228—11.6%
——3——CVE-2025-21636—11.6%
——3——CVE-2022-50778—11.6%
——3——CVE-2025-6641—11.6%
——3——CVE-2022-30539—11.6%
——3——