Vulnerabilities exploitable today
359,665in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,517
- High11,192
- Medium7,126
- Low650
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-53048—10.9%
——3——CVE-2022-27242—10.9%
——3——CVE-2026-72327.2 HIG10.9%
——3The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit chain combines a server-side gap — where composite matrix sub-field keys such as field2_0 and field2_1 are never passed through the sanitization loop and are stored raw via $wpdb->insert() — with a client-side gap where DOMPurify is only invoked when typeof field.value === 'string', but matrix values arrive from the server as arrays, bypassing the check before being mapped to strings and injected into the DOM. Additionally, the same sink is reachable via a second attack vector: array-typed field values are passed through htmlentities() on submission but later reversed by html_entity_decode() at formcraft-main.php:2608 and :2122, restoring the malicious payload before storage and rendering.22dCVE-2024-3058—10.9%
——3——CVE-2026-728098.0 HIG10.9%
——3SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0.1) for a specific set of endpoints (including /api/system/exit, getNetwork, getWorkspaceInfo, /assets/*, and /export/*). These localhost bypasses sit outside the access auth code gate, so they apply even when an access auth code is configured. Because the fixed-port reverse proxy forwards requests to the kernel over loopback without injecting an authentication token and does not configure trusted proxies, a request forwarded through this proxy reaches the kernel with RemoteAddr = 127.0.0.1. If the fixed-port proxy is bound to a network interface, this could allow a remote unauthenticated attacker to obtain admin access on the affected endpoints; however, per the advisory this remote forwarding behavior was established only by code inspection and was not reproduced end-to-end.3hCVE-2025-21934—10.9%
——3——CVE-2025-47754—10.9%
——3——CVE-2026-16956.1 MED10.9%
——3An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication on an unknown application (unknown client_id).
This vulnerability only affects the error page of the OAuth server.36dCVE-2026-54006—10.9%
——3——CVE-2025-1108—10.9%
——3——CVE-2024-53154—10.9%
——3——CVE-2023-28402—10.9%
——3——CVE-2025-22054—10.9%
——3——CVE-2024-34580—10.9%
——3——CVE-2025-47753—10.9%
——3——CVE-2023-41095—10.9%
——3——CVE-2026-572305.4 MED10.9%
——3OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise editions with multi-tenancy enabled built ClickHouse queries by inserting user input into the query string, including two positions that took input without escaping, allowing an authenticated member to read any ClickHouse table through blind boolean and time-based exfiltration and to break the project's session search for all viewers until the stored key is removed. This issue is fixed in version 1.27.0.32dCVE-2025-47755—10.9%
——3——CVE-2026-144179.6 CRI10.9%
——3Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)43dCVE-2024-47895—10.9%
——3——CVE-2024-56763—10.9%
——3——CVE-2023-22874—10.9%
——3——CVE-2023-40437—10.9%
——3——CVE-2024-53128—10.9%
——3——CVE-2025-23284—10.9%
——3——CVE-2025-47751—10.9%
——3——CVE-2024-53129—10.9%
——3——CVE-2026-704328.8 HIG10.9%
——3A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.9dCVE-2024-56622—10.9%
——3——CVE-2025-50367—10.9%
——3——CVE-2024-56787—10.9%
——3——CVE-2025-36161—10.9%
——3——CVE-2025-52363—10.9%
——3——CVE-2025-47757—10.9%
——3——CVE-2025-22844—10.9%
——3——CVE-2026-23032—10.9%
——3——CVE-2026-32019—10.9%
——3——CVE-2026-572046.5 MED10.9%
——3pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length value. This issue has been fixed in version 6.13.3.39dCVE-2022-50649—10.9%
——3——CVE-2026-40213—10.9%
——3——