Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,722
- Medium6,710
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-34962—28.2%
——8——CVE-2025-46888—28.2%
——8——CVE-2025-64218—28.2%
——8——CVE-2021-34967—28.2%
——8——CVE-2025-64725—28.2%
——8——CVE-2026-10086—28.2%
——8——CVE-2024-4697—28.2%
——8——CVE-2026-69106.4 MED28.2%
——8The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide_products` (and `filter_products`) attributes in versions up to and including 2.2. This is due to insufficient input sanitization and output escaping in the `bookero_products()` function — the raw attribute value is concatenated directly into an inline `<script>` block without any escaping. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages that will execute whenever a user accesses the injected page.69dCVE-2025-46909—28.2%
——8——CVE-2021-34963—28.2%
——8——CVE-2017-14159—28.2%
——8——CVE-2025-46948—28.2%
——8——CVE-2025-46916—28.2%
——8——CVE-2025-46933—28.2%
——8——CVE-2025-52196—28.2%
——8——CVE-2025-46955—28.2%
——8——CVE-2021-34956—28.2%
——8——CVE-1999-1552—28.2%
——8——CVE-1999-1071—28.2%
——8——CVE-2021-34948—28.2%
——8——CVE-2026-121706.4 MED28.2%
——8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.69dCVE-2023-28478—28.2%
——8——CVE-2026-143436.4 MED28.2%
——8The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode.69dCVE-2026-151566.4 MED28.2%
——8The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.56dCVE-2026-1154—28.2%
——8——CVE-2025-15237—28.2%
——8——CVE-2026-157596.4 MED28.2%
——8The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.61dCVE-2025-46881—28.2%
——8——CVE-2024-3563—28.2%
——8——CVE-2025-49618—28.2%
——8——CVE-2021-34966—28.2%
——8——CVE-2024-41453—28.2%
——8——CVE-2021-34960—28.2%
——8——CVE-2026-4610—28.2%
——8——CVE-2021-34952—28.2%
——8——CVE-2024-5457—28.2%
——8——CVE-2025-4177—28.2%
——8——CVE-2025-46946—28.2%
——8——CVE-2025-46974—28.2%
——8——CVE-2026-507827.5 HIG28.2%
——8Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload to read arbitrary files from the server via an out-of-band attack.48d