Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-53709—26.2%
——8——CVE-2024-5677—26.2%
——8——CVE-2024-3937—26.2%
——8——CVE-2025-0628—26.2%
——8——CVE-2005-1726—26.2%
——8——CVE-2025-15197—26.2%
——8——CVE-2021-28713—26.2%
——8——CVE-2026-12588—26.2%
——8An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.62dCVE-2025-54164—26.2%
——8——CVE-2025-14307—26.2%
——8——CVE-2025-10110—26.2%
——8——CVE-2024-37363—26.2%
——8——CVE-2021-33057.8 HIG26.2%
——8Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.69dCVE-2025-96066.3 MED26.2%
——8A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing a manipulation of the argument cod_agenda results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.12 addresses this issue. Upgrading the affected component is advised. The vendor confirms: "The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced."8hCVE-2005-2785—26.2%
——8——CVE-2024-4381—26.2%
——8——CVE-2026-35415—26.2%
——8——CVE-2025-67712—26.1%
——8——CVE-2018-11294—26.1%
——8——CVE-2014-0135—26.1%
——8——CVE-2024-56366—26.1%
——8——CVE-2023-47247—26.1%
——8——CVE-2021-30922—26.1%
——8——CVE-2012-2103—26.1%
——8——CVE-2006-2443—26.1%
——8——CVE-2026-9794—26.1%
——8——CVE-2016-5525—26.1%
——8——CVE-2005-0542—26.1%
——8——CVE-2016-0458—26.1%
——8——CVE-2026-127346.4 MED26.1%
——8The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'connectorWidth' Block Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.71dCVE-2024-56409—26.1%
——8——CVE-2024-9325—26.1%
——8——CVE-2005-1887—26.1%
——8——CVE-2019-15346—26.1%
——8——CVE-2026-11597—26.1%
——8——CVE-2026-121546.4 MED26.1%
——8The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev() method, which passes the raw shortcode attribute through Feed_Old::get_feed() into the View::render() method, where it is echoed directly into the data-id HTML attribute without esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.70dCVE-2024-5539—26.1%
——8——CVE-2026-13247—26.1%
——8——CVE-2025-29606—26.1%
——8——CVE-2026-156526.4 MED26.1%
——8The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.61d