Vulnerabilities exploitable today
359,691in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,519
- High11,197
- Medium7,131
- Low645
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-22143—11.2%
——3——CVE-2024-11703—11.2%
——3——CVE-2022-34429—11.2%
——3——CVE-2026-160417.5 HIG11.2%
——3The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.8dCVE-2019-25705—11.2%
——3——CVE-2024-1336—11.2%
——3——CVE-2018-11968—11.2%
——3——CVE-2023-41950—11.2%
——3——CVE-2023-45068—11.2%
——3——CVE-2018-11857—11.2%
——3——CVE-2023-23493—11.2%
——3——CVE-2026-21393—11.2%
——3——CVE-2023-45102—11.2%
——3——CVE-2023-45047—11.2%
——3——CVE-2022-50038—11.2%
——3——CVE-2024-33005—11.2%
——3——CVE-2022-49788—11.2%
——3——CVE-2023-46078—11.2%
——3——CVE-2023-25396—11.2%
——3——CVE-2023-27433—11.2%
——3——CVE-2025-34258—11.2%
——3——CVE-2025-43534—11.2%
——3——CVE-2023-46779—11.2%
——3——CVE-2023-27615—11.2%
——3——CVE-2026-558253.1 LOW11.2%
——3Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segments and make the job attachment download endpoint read a file from another job directory inside var/job-attachments. The controller authorizes only the jobUuid route parameter. The later attachment lookup joins that authorized job UUID with the attacker-controlled identifier, then passes the combined path to the virtual filesystem. VirtualFilesystem::resolve() canonicalizes the whole path and only rejects paths that escape the filesystem mount, so authorized-job/../victim-job/debug_log.csv becomes victim-job/debug_log.csv. This is a cross-job authorization bypass for known job attachment paths. It is not a practical brute-force against unknown jobs because job directories are UUID v4 values.14dCVE-2019-25701—11.2%
——3——CVE-2018-11858—11.2%
——3——CVE-2018-3588—11.2%
——3——CVE-2018-9357—11.2%
——3——CVE-2022-50812—11.2%
——3——CVE-2026-22875—11.2%
——3——CVE-2022-34866—11.2%
——3——CVE-2024-1338—11.2%
——3——CVE-2022-49978—11.2%
——3——CVE-2020-11183—11.2%
——3——CVE-2023-41668—11.2%
——3——CVE-2024-8645—11.2%
——3——CVE-2022-50008—11.2%
——3——CVE-2023-41854—11.1%
——3——CVE-2001-0682—11.1%
——3——