Vulnerabilities exploitable today
359,691in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,519
- High11,197
- Medium7,131
- Low645
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-2760—11.1%
——3——CVE-2026-1433—11.1%
——3uniFLOW Universal Login Manager (ULM) Standalone
contains an information disclosure vulnerability that may allow an
authenticated administrator to access sensitive configuration information
through the ULM Remote User Interface (RUI). Exploitation requires
administrative privileges and may disclose configuration data associated with
SMTP or LDAP integrations. ULM deployments connected to uniFLOW Server or
uniFLOW Online are not affected.40dCVE-2025-49932—11.1%
——3——CVE-2023-44995—11.1%
——3——CVE-2025-57989—11.1%
——3——CVE-2021-26364—11.1%
——3——CVE-2025-47822—11.1%
——3——CVE-2026-14516.1 MED11.1%
——3The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.24dCVE-2024-40933—11.1%
——3——CVE-2022-27493—11.1%
——3——CVE-2023-52905—11.1%
——3——CVE-2023-45656—11.1%
——3——CVE-2024-13813—11.1%
——3——CVE-2025-49938—11.1%
——3——CVE-2023-45641—11.1%
——3——CVE-2026-336845.3 MED11.1%
——3WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during account registration. The set_api_signUp method in the API plugin accepts emailVerified, canUpload, canStream, and canCreateMeet parameters from user-supplied input and applies them to newly created accounts without verifying that the request was authenticated with a valid APISecret. By self-granting account attributes, attackers can mark their own accounts as email-verified without owning the address (bypassing email-gated functionality) and award themselves upload, streaming, and meeting-creation permissions, circumventing administrator access controls that intentionally restrict these capabilities for new users. This issue has been fixed in version 29.030dCVE-2001-0682—11.1%
——3——CVE-2023-41854—11.1%
——3——CVE-2025-49927—11.1%
——3——CVE-2025-49933—11.1%
——3——CVE-2026-342125.4 MED11.1%
——3Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralization of attachment URLs in Docmost allows a low-privileged authenticated user to store a malicious `javascript:` URL inside an attachment node in page content. When another user views the page and activates the attachment link/icon, attacker-controlled JavaScript executes in the context of the Docmost origin. Version 0.71.0 patches the issue.21dCVE-2025-40939—11.1%
——3——CVE-2022-509596.1 MED11.1%
——3WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.22dCVE-2017-13320—11.1%
——3——CVE-2022-25841—11.1%
——3——CVE-2025-26997—11.1%
——3——CVE-2022-34412—11.1%
——3——CVE-2025-23986—11.1%
——3——CVE-2023-52783—11.1%
——3——CVE-2025-14991—11.1%
——3——CVE-2023-39165—11.1%
——3——CVE-2026-535018.2 HIG11.1%
——3Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can insert the same signature multiple times in the URL and manipulate the final URL used for validation. This allows crafting URLs where the validated string differs from the actual requested resource, enabling loading images from unintended domains or paths. This issue is fixed in 7.8.0.15dCVE-2022-33209—11.1%
——3——CVE-2023-40199—11.1%
——3——CVE-2025-23983—11.1%
——3——CVE-2024-52271—11.1%
——3——CVE-2023-52911—11.1%
——3——CVE-2022-34488—11.1%
——3——CVE-2026-2540—11.1%
——3——CVE-2024-52277—11.1%
——3——