Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,199
- High7,814
- Medium6,363
- Low706
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-143436.4 MED28.2%
——8The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode.69dCVE-2026-121706.4 MED28.2%
——8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.69dCVE-2021-34961—28.2%
——8——CVE-2021-34950—28.2%
——8——CVE-2026-1154—28.2%
——8——CVE-2025-46926—28.2%
——8——CVE-2019-0088—28.2%
——8——CVE-2024-49551—28.2%
——8——CVE-2021-34965—28.2%
——8——CVE-2025-10763—28.2%
——8——CVE-2025-46922—28.2%
——8——CVE-2024-49553—28.2%
——8——CVE-2025-46951—28.2%
——8——CVE-2025-46887—28.2%
——8——CVE-2025-46941—28.2%
——8——CVE-2021-34958—28.2%
——8——CVE-2005-2180—28.2%
——8——CVE-2026-46536.4 MED28.2%
——8The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to and including 3.6.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.69dCVE-2025-46940—28.2%
——8——CVE-2021-34953—28.2%
——8——CVE-2021-34948—28.2%
——8——CVE-2023-28478—28.2%
——8——CVE-2006-0512—28.2%
——8——CVE-2020-4083—28.2%
——8——CVE-2025-46880—28.2%
——8——CVE-2021-34955—28.2%
——8——CVE-2025-58951—28.2%
——8——CVE-2026-6178—28.2%
——8——CVE-2025-5037—28.2%
——8——CVE-2024-12548—28.2%
——8——CVE-2025-46927—28.2%
——8——CVE-2026-1145—28.2%
——8——CVE-2025-139686.4 MED28.2%
——8The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.63dCVE-2025-3467—28.2%
——8——CVE-2025-47077—28.2%
——8——CVE-2025-46893—28.2%
——8——CVE-2025-46965—28.2%
——8——CVE-2025-59557—28.2%
——8——CVE-2026-88926.4 MED28.2%
——8The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the malicious payload is stored in post meta rather than post_content, WordPress's unfiltered_html capability restriction does not apply, meaning contributors who lack that capability can still inject executable HTML via the address meta fields such as cmbd_address, cmbd_cityTown, cmbd_stateCounty, cmbd_postalcode, cmbd_region, and cmbd_country.72dCVE-2025-46906—28.2%
——8——