Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,698
- High11,576
- Medium7,298
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-190899.8 CRI10.5%
——3The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules.21hCVE-2021-36924—10.5%
——3——CVE-2025-57913—10.5%
——3——CVE-2024-53849—10.5%
——3——CVE-2023-54197—10.5%
——3——CVE-2026-22748—10.5%
——3——CVE-2025-64781—10.5%
——3——CVE-2026-42937—10.5%
——3——CVE-2024-35560—10.5%
——3——CVE-2024-34015—10.5%
——3——CVE-2024-53117—10.5%
——3——CVE-2022-50206—10.5%
——3——CVE-2025-13107—10.5%
——3——CVE-2018-11299—10.5%
——3——CVE-2026-133626.4 MED10.5%
——3The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the attacker to create a sendpulse_form post containing a benign SendPulse loader script tag alongside arbitrary HTML (e.g., an img onerror payload), which bypasses the allow-list check and executes in the browser of any user — including administrators — who previews or views a page rendering the [sendpulse-form] shortcode.18hCVE-2025-64524—10.5%
——3——CVE-2025-57938—10.5%
——3——CVE-2024-53048—10.5%
——3——CVE-2025-44004—10.5%
——3——CVE-2026-542915.9 MED10.5%
——3pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.35dCVE-2019-14056—10.5%
——3——CVE-2019-10615—10.5%
——3——CVE-2019-13999—10.5%
——3——CVE-2025-55126—10.5%
——3——CVE-2025-26698—10.5%
——3——CVE-2024-20986—10.5%
——3——CVE-2026-137787.8 HIG10.5%
——3Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)42dCVE-2026-23622—10.4%
——3——CVE-2026-12129—10.5%
——3——CVE-2024-53118—10.5%
——3——CVE-2025-52486—10.5%
——3——CVE-2025-54269—10.5%
——3——CVE-2024-0149—10.5%
——3——CVE-2025-61842—10.5%
——3——CVE-2026-150106.4 MED10.5%
——3The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature. This is due to insufficient input sanitization in bsp_topic_fields_form_save() (which writes $_POST['bsp_topic_fields_label{n}'] directly to post meta via update_post_meta() with no filtering) and missing output escaping in bsp_topic_content_append_topic_fields() (which concatenates the stored meta value into an HTML <span> and echoes it via apply_filters/echo without esc_html()). This makes it possible for authenticated attackers, with Subscriber-level access and above (who have bbPress topic-creation privileges), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, including unauthenticated visitors.31dCVE-2019-10596—10.5%
——3——CVE-2025-60163—10.5%
——3——CVE-2025-54270—10.5%
——3——CVE-2024-47058—10.5%
——3——CVE-2026-562206.5 MED10.4%
——3Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows read-only org members to insert OTA manifest rows. Attackers with read-only org access can inject malicious manifest entries with arbitrary s3_path values that are served to devices via the unauthenticated /updates endpoint, enabling OTA metadata poisoning and potential malicious asset delivery.36d