Vulnerabilities exploitable today
363,765in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,923
- High12,261
- Medium7,478
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-665955.9 MED—
——0Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.21hCVE-2026-665977.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.20hCVE-2026-281649.6 CRI—
——0Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery.
This issue affects Easy Elementor Addons: from n/a through 2.3.7.22hCVE-2026-740117.6 HIG—
——0Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection.
This issue affects InfiniteWP Client: from n/a through 1.13.9.20hCVE-2026-51231——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.21dCVE-2026-157069.8 CRI—
——0Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass.
This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.20hCVE-2026-769996.3 MED—
——0A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.19hCVE-2023-54369——
——0Rejected reason: This CVE ID has been rejected.10dCVE-2023-54368——
——0Rejected reason: This CVE ID has been rejected.10dCVE-2026-6260——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.18hCVE-2026-6822——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.18hCVE-2026-14253——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.36dCVE-2026-22655——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.11dCVE-2026-17590——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-32475. Reason: This candidate is a reservation duplicate of CVE-2026-32475. Notes: All CVE users should reference CVE-2026-32475 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.2dCVE-2026-22654——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.11dCVE-2026-76022——
——0Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)16hCVE-2026-775064.8 MED—
——0Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.16hCVE-2026-17592——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.21dCVE-2023-54385——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.16dCVE-2026-74227——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.2dCVE-2023-54384——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.16dCVE-2023-54382——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.16dCVE-2023-54381——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.16dCVE-2023-54380——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.16dCVE-2026-169467.8 HIG—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap buffer overflow.15hCVE-2026-171388.1 HIG—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.15hCVE-2026-171419.8 CRI—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.15hCVE-2026-550137.1 HIG—
——0Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.15hCVE-2026-51276——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.21dCVE-2026-550155.5 MED—
——0Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.15hCVE-2026-6580110.0 CRI—
——0Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.15hCVE-2026-53569——
——0Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce read permission before modifying _liked_by metadata or a Note seen state. An authenticated user can interact with documents or notes that the user cannot read, disclosing resource existence and modifying resource-associated metadata. No released fixed version is available as of this review.18hCVE-2026-6581610.0 CRI—
——0Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.15hCVE-2023-54367——
——0Rejected reason: This CVE ID has been rejected.10dCVE-2022-50974——
——0Rejected reason: This CVE ID has been rejected.10dCVE-2026-20415—0.0%
——0——CVE-2026-51239——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.21dCVE-2026-51240——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.21dCVE-2026-66737——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.23dCVE-2026-6890——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21d