Vulnerabilities exploitable today
356,679in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,534
- High10,642
- Medium6,742
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-21997—8.1%
——2——CVE-2024-37458—8.1%
——2——CVE-2022-49949—8.1%
——2——CVE-2025-62119—8.1%
——2——CVE-2026-101004.4 MED8.1%
——2The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, Link Color) in versions up to and including 1.0.3. This is due to insufficient input sanitization of the color option values (they were registered with register_setting() and stored via the Settings API/update_option() with no sanitize_callback) combined with the values being output into a <style> block on wp-login.php using esc_attr(), which is incorrect for a CSS context (it does not escape ;, {, }, / or *). This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary CSS rules into the login page that are rendered for all unauthenticated visitors, enabling UI-redress and credential-phishing attacks.17dCVE-2026-33739—8.1%
——2——CVE-2025-64143—8.1%
——2——CVE-2025-68289—8.1%
——2——CVE-2025-68288—8.1%
——2——CVE-2024-56668—8.1%
——2——CVE-2025-30417—8.1%
——2——CVE-2024-4607—8.1%
——2——CVE-2025-68200—8.1%
——2——CVE-2023-54112—8.1%
——2——CVE-2025-64094—8.1%
——2——CVE-2025-54470—8.1%
——2——CVE-2025-39999—8.1%
——2——CVE-2022-41802—8.1%
——2——CVE-2026-139844.3 MED8.1%
——2Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)37dCVE-2022-21239—8.1%
——2——CVE-2023-54309—8.1%
——2——CVE-2025-12023—8.1%
——2——CVE-2025-40352—8.1%
——2——CVE-2025-2141—8.1%
——2——CVE-2025-67261—8.1%
——2——CVE-2025-62149—8.1%
——2——CVE-2026-160275.4 MED8.1%
——2Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery.
This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0.1dCVE-2025-30418—8.1%
——2——CVE-2025-40164—8.1%
——2——CVE-2025-30084—8.1%
——2——CVE-2023-32840—8.1%
——2——CVE-2023-54265—8.1%
——2——CVE-2026-141716.1 MED8.1%
——2An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.9dCVE-2023-54051—8.1%
——2——CVE-2024-37431—8.1%
——2——CVE-2026-118765.0 MED8.1%
——2In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all users and tenants. This includes stack component details, service connector information, and user IDs of stack owners. The vulnerability arises from two issues: missing endpoint-level RBAC checks and the use of a server-side `Client()` that bypasses the RBAC enforcement layer by directly accessing the database through `SqlZenStore`. This exposes sensitive information such as infrastructure topology, service connector details, stack ownership, and deployment metadata, potentially enabling cross-tenant reconnaissance and further attacks in multi-tenant ZenML Pro/Cloud deployments.16dCVE-2024-37235—8.1%
——2——CVE-2023-6362—8.1%
——2——CVE-2025-66359—8.1%
——2——CVE-2019-25637—8.1%
——2——