Vulnerabilities exploitable today
356,923in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,543
- High10,564
- Medium6,729
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-31013—9.3%
——3——CVE-2024-36956—9.3%
——3——CVE-2024-51631—9.3%
——3——CVE-2024-54438—9.3%
——3——CVE-2023-29164—9.3%
——3——CVE-2024-51634—9.3%
——3——CVE-2025-61550—9.3%
——3——CVE-2026-573756.5 MED9.3%
——3Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4.28dCVE-2024-20323—9.3%
——3——CVE-2025-711655.4 MED9.3%
——3Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status functionality. The path parameter is reflected into the HTML response without proper output encoding in include/admin/Tools/Status.php. An authenticated attacker can supply crafted input containing HTML or JavaScript, resulting in arbitrary script execution in the context of an authenticated user's browser session.27dCVE-2022-50681—9.3%
——3——CVE-2024-51637—9.3%
——3——CVE-2024-38600—9.3%
——3——CVE-2024-54394—9.3%
——3——CVE-2024-54399—9.3%
——3——CVE-2022-43901—9.3%
——3——CVE-2025-711665.4 MED9.3%
——3Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status move message handling. The path parameter is reflected into the HTML output without proper output encoding in include/admin/Tools/Status.php. An authenticated attacker can supply crafted input containing HTML or JavaScript, resulting in arbitrary script execution in the context of an authenticated user's browser session.27dCVE-2025-711645.4 MED9.3%
——3Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Editing component. The images parameter (submitted as images[] in a POST request) is reflected into an HTML href attribute without proper context-aware output encoding in include/tool/Editing.php. An authenticated attacker with editing privileges can supply a JavaScript pseudo-protocol (e.g., javascript:) to trigger arbitrary JavaScript execution in the context of the victim's browser session.27dCVE-2026-4968—9.3%
——3——CVE-2025-40675—9.3%
——3——CVE-2024-51638—9.3%
——3——CVE-2025-71238—9.3%
——3——CVE-2024-10389—9.3%
——3——CVE-2024-21859—9.3%
——3——CVE-2024-50534—9.3%
——3——CVE-2023-32764—9.3%
——3——CVE-2024-20320—9.3%
——3——CVE-2023-51491—9.3%
——3——CVE-2024-54391—9.3%
——3——CVE-2024-51636—9.3%
——3——CVE-2025-58759—9.3%
——3——CVE-2022-43703—9.3%
——3——CVE-2024-54404—9.3%
——3——CVE-2025-21872—9.3%
——3——CVE-2026-274095.3 MED9.3%
——3Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Webba Booking: from n/a through 6.4.13.40dCVE-2026-254036.5 MED9.3%
——3Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.4dCVE-2024-54409—9.3%
——3——CVE-2023-53007—9.3%
——3——CVE-2025-40829—9.3%
——3——CVE-2026-654996.5 MED9.3%
——3Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.18d