Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,289
- High9,343
- Medium5,276
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-274027.1 HIG16.4%
——5Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.58dCVE-2026-573617.1 HIG16.4%
——5Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.58dCVE-2023-4307—16.4%
——5——CVE-2023-4150—16.4%
——5——CVE-2026-573977.1 HIG16.4%
——5Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.37dCVE-2024-34722—16.4%
——5——CVE-2026-319815.9 MED16.4%
——5A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a victim views the affected data in the Diagram tab and Graph view, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.18dCVE-2025-58324—16.4%
——5——CVE-2024-13505—16.4%
——5——CVE-2023-1088—16.4%
——5——CVE-2023-0504—16.4%
——5——CVE-2023-1087—16.4%
——5——CVE-2023-0499—16.4%
——5——CVE-2023-5862—16.4%
——5——CVE-2026-577327.1 HIG16.4%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows DOM-Based XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.4.47dCVE-2025-31990—16.4%
——5——CVE-2026-22254—16.4%
——5——CVE-2023-2271—16.4%
——5——CVE-2026-458106.8 MED16.4%
——5Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file comment, to read the content of all comments. It is recommended that the Nextcloud Server is upgraded to 31.0.12 or 32.0.3. It is recommended that the Nextcloud Enterprise Server is upgraded to 21.0.9.20, 22.2.10.35, 23.0.12.31, 24.0.12.30, 25.0.13.25, 26.0.13.22, 27.1.11.22, 28.0.14.13, 29.0.16.10, 30.0.17.5, 31.0.12 or 32.0.339dCVE-2024-47142—16.4%
——5——CVE-2025-11632—16.4%
——5——CVE-2026-573997.1 HIG16.4%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy & VPN Blocker Proxy & VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy & VPN Blocker: from n/a through <= 3.5.8.47dCVE-2023-20050—16.4%
——5——CVE-2026-619477.1 HIG16.4%
——5Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.37dCVE-2026-57336—16.4%
——5——CVE-2026-573567.1 HIG16.4%
——5Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.58dCVE-2026-573947.1 HIG16.4%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14.47dCVE-2019-25244—16.4%
——5——CVE-2025-32364—16.4%
——5——CVE-2025-48127—16.4%
——5——CVE-2026-0548—16.4%
——5——CVE-2026-573587.1 HIG16.4%
——5Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions.58dCVE-2026-5111—16.4%
——5——CVE-2026-577187.1 HIG16.4%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 2.0.12.47dCVE-2025-67621—16.4%
——5——CVE-2026-595167.1 HIG16.4%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1.47dCVE-2026-574097.1 HIG16.4%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.1.0.47dCVE-2026-573877.1 HIG16.4%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu allows Stored XSS.This issue affects picu: from n/a through <= 3.5.1.47dCVE-2026-573827.1 HIG16.4%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8.47dCVE-2026-573887.1 HIG16.4%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.44.47d