Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,289
- High9,343
- Medium5,276
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-576717.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions.58dCVE-2026-577047.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.37dCVE-2024-467817.8 HIG16.3%
——5In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix missing cleanup on rollforward recovery error
In an error injection test of a routine for mount-time recovery, KASAN
found a use-after-free bug.
It turned out that if data recovery was performed using partial logs
created by dsync writes, but an error occurred before starting the log
writer to create a recovered checkpoint, the inodes whose data had been
recovered were left in the ns_dirty_files list of the nilfs object and
were not freed.
Fix this issue by cleaning up inodes that have read the recovery data if
the recovery routine fails midway before the log writer starts.26dCVE-2026-576707.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.58dCVE-2026-56051—16.3%
——5——CVE-2026-578097.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.37dCVE-2026-199276.3 MED16.3%
——5A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload Endpoint. Performing a manipulation of the argument params.url results in server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.9.8-hotfix1 and 0.9.8 is sufficient to resolve this issue. The patch is named a599007325efe780a21b3537ecce3ca25635c926. It is suggested to upgrade the affected component.9dCVE-2026-573447.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.58dCVE-2026-574237.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3.8.47dCVE-2026-574287.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.37dCVE-2026-57322—16.3%
——5——CVE-2022-50824—16.3%
——5——CVE-2026-595177.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.37dCVE-2025-54499—16.3%
——5——CVE-2026-574157.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codemenschen Gift Vouchers gift-voucher allows Stored XSS.This issue affects Gift Vouchers: from n/a through <= 4.7.0.47dCVE-2026-56041—16.3%
——5——CVE-2026-56042—16.3%
——5——CVE-2022-50678—16.3%
——5——CVE-2026-56011—16.3%
——5——CVE-2026-12001—16.3%
——5A hardcoded credential
vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is
embedded within a password file in the firmware image and may be recovered
through firmware analysis.
Successful
exploitation could result in unauthorized access to privileged functions on
affected devices.18dCVE-2026-574117.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views – Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views – Complete Entry Management for Contact Form 7: from n/a through <= 3.2.2.47dCVE-2023-53831—16.3%
——5——CVE-2020-25688—16.3%
——5——CVE-2026-274257.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.58dCVE-2026-577067.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6.47dCVE-2026-574267.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions.58dCVE-2026-274087.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.58dCVE-2025-691547.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.58dCVE-2026-576997.1 HIG16.3%
——5Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.37dCVE-2026-56039—16.3%
——5——CVE-2026-595127.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.37dCVE-2026-574177.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme Cart Lift cart-lift allows Stored XSS.This issue affects Cart Lift: from n/a through <= 3.1.57.47dCVE-2026-577357.1 HIG16.3%
——5Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.37dCVE-2026-573767.1 HIG16.3%
——5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.3.47dCVE-2026-598395.5 MED16.3%
——5A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>18dCVE-2024-56534—16.3%
——5——CVE-2025-7812—16.3%
——5——CVE-2026-680858.0 HIG16.3%
——5In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
HCI_UART_SENDING bit in tx_state means write_work is pending and blocks
queueing it again. Currently this bit is not cleared when canceling the
work in hci_uart_close(), which blocks future writes when device is
reopened later if write_work was pending.
Fix by clearing HCI_UART_SENDING when canceling the work.
Also make clearing of tx_skb safe by using disable_work_sync +
enable_work instead of just cancel_work_sync. hci_uart_flush() purges
the proto tx queue so we can cancel the pending write_work there,
instead of doing it just in hci_uart_close(). Re-enable and possibly
requeue the work after queue flush.13dCVE-2024-48881—16.3%
——5——CVE-2025-32984—16.3%
——5——