Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,289
- High9,343
- Medium5,276
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-25502—16.3%
——5——CVE-2026-56045—16.3%
——5——CVE-2026-763257.3 HIG16.3%
——5In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious ui-tour knowledge object that matches an auto-tour page name and share the object at the app level. The object can execute arbitrary JavaScript in the browser of another authenticated user who visits a standard Splunk Web page. The JavaScript could expose all relevant data and affect system integrity within the second user permissions. The Cross-Site Scripting (XSS) vulnerability is possible because Splunk Web resolves auto-tour entries from the app namespace and uses untrusted tour content when building the tour image.8dCVE-2026-56051—16.3%
——5——CVE-2026-199276.3 MED16.3%
——5A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload Endpoint. Performing a manipulation of the argument params.url results in server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.9.8-hotfix1 and 0.9.8 is sufficient to resolve this issue. The patch is named a599007325efe780a21b3537ecce3ca25635c926. It is suggested to upgrade the affected component.9dCVE-2024-467817.8 HIG16.3%
——5In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix missing cleanup on rollforward recovery error
In an error injection test of a routine for mount-time recovery, KASAN
found a use-after-free bug.
It turned out that if data recovery was performed using partial logs
created by dsync writes, but an error occurred before starting the log
writer to create a recovered checkpoint, the inodes whose data had been
recovered were left in the ns_dirty_files list of the nilfs object and
were not freed.
Fix this issue by cleaning up inodes that have read the recovery data if
the recovery routine fails midway before the log writer starts.26dCVE-2026-577047.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.37dCVE-2026-576707.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.58dCVE-2026-573447.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.58dCVE-2026-578097.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.37dCVE-2026-576757.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions.58dCVE-2025-67851—16.3%
——5——CVE-2025-10223—16.3%
——5——CVE-2025-15560—16.3%
——5——CVE-2026-56047—16.3%
——5——CVE-2025-7767—16.3%
——5——CVE-2024-46761—16.3%
——5——CVE-2026-577257.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.47dCVE-2026-48485—16.3%
——5——CVE-2026-578167.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.15.0.8.47dCVE-2026-573507.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.58dCVE-2020-25688—16.3%
——5——CVE-2025-61924—16.3%
——5——CVE-2026-577697.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.37dCVE-2026-577347.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.47dCVE-2022-30712—16.3%
——5——CVE-2020-25533—16.3%
——5——CVE-2018-9511—16.3%
——5——CVE-2024-29786—16.3%
——5——CVE-2026-576737.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Optimole <= 4.2.7 versions.58dCVE-2026-574177.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme Cart Lift cart-lift allows Stored XSS.This issue affects Cart Lift: from n/a through <= 3.1.57.47dCVE-2026-573767.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.3.47dCVE-2026-56039—16.3%
——5——CVE-2026-577357.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.37dCVE-2026-595127.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.37dCVE-2022-50824—16.3%
——5——CVE-2026-577457.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Reflected XSS.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.47dCVE-2026-576687.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.2.2.47dCVE-2026-574237.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3.8.47dCVE-2026-574157.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codemenschen Gift Vouchers gift-voucher allows Stored XSS.This issue affects Gift Vouchers: from n/a through <= 4.7.0.47d