Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,722
- Medium6,710
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-34963—28.2%
——8——CVE-2024-3563—28.2%
——8——CVE-2025-46916—28.2%
——8——CVE-2025-46909—28.2%
——8——CVE-2025-46948—28.2%
——8——CVE-2025-26519—28.2%
——8——CVE-2024-4787—28.2%
——8——CVE-2025-46965—28.2%
——8——CVE-2026-88926.4 MED28.2%
——8The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the malicious payload is stored in post meta rather than post_content, WordPress's unfiltered_html capability restriction does not apply, meaning contributors who lack that capability can still inject executable HTML via the address meta fields such as cmbd_address, cmbd_cityTown, cmbd_stateCounty, cmbd_postalcode, cmbd_region, and cmbd_country.72dCVE-2025-46906—28.2%
——8——CVE-2025-59557—28.2%
——8——CVE-2021-34960—28.2%
——8——CVE-2024-41453—28.2%
——8——CVE-2025-46883—28.2%
——8——CVE-2025-46891—28.2%
——8——CVE-2019-11146—28.2%
——8——CVE-2026-4610—28.2%
——8——CVE-2021-34966—28.2%
——8——CVE-2025-64725—28.2%
——8——CVE-2024-49551—28.2%
——8——CVE-2021-34965—28.2%
——8——CVE-2026-10086—28.2%
——8——CVE-2024-4697—28.2%
——8——CVE-2026-69106.4 MED28.2%
——8The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide_products` (and `filter_products`) attributes in versions up to and including 2.2. This is due to insufficient input sanitization and output escaping in the `bookero_products()` function — the raw attribute value is concatenated directly into an inline `<script>` block without any escaping. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages that will execute whenever a user accesses the injected page.69dCVE-2025-46956—28.2%
——8——CVE-2024-4868—28.2%
——8——CVE-2021-34967—28.2%
——8——CVE-2026-175529.1 CRI28.2%
——8Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call.
When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a forward slash ('/').
When the rewrite base does not contain a path (which is the standard given in the SYNOPSIS), an attacker can create a request that changes the hostname. A request target starting with an at-sign ('@') changes the base to a RFC 3986 userinfo component.
For example, a rewrite base of "https://example.com" with the submitted request "GET @192.168.1.2/" will send a request to "https://example.com@192.168.1.2/", with the rendered content returned to the attacker.
This allows an attacker to access internal or restricted hosts that only the webserver has access to.50dCVE-2026-151566.4 MED28.2%
——8The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.56dCVE-2021-34956—28.2%
——8——CVE-2026-121706.4 MED28.2%
——8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.69dCVE-1999-1071—28.2%
——8——CVE-2026-143436.4 MED28.2%
——8The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode.69dCVE-2025-47075—28.2%
——8——CVE-2026-1145—28.2%
——8——CVE-2026-6178—28.2%
——8——CVE-2025-139686.4 MED28.2%
——8The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.63dCVE-2025-46908—28.2%
——8——CVE-2025-46882—28.2%
——8——CVE-2024-12548—28.2%
——8——