Vulnerabilities exploitable today
358,897in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,704
- High11,656
- Medium7,416
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-27899—9.7%
——3——CVE-2025-31083—9.7%
——3——CVE-2026-76406.4 MED9.7%
——3The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortcode in all versions up to, and including, 8.3.5. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.29dCVE-2025-40142—9.7%
——3——CVE-2025-26742—9.7%
——3——CVE-2026-664385.3 MED9.7%
——3Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.16dCVE-2026-619755.3 MED9.7%
——3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.30dCVE-2025-68887—9.7%
——3——CVE-2026-156526.4 MED9.7%
——3The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.28dCVE-2024-235755.3 MED9.7%
——3HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.26dCVE-2022-28197—9.7%
——3——CVE-2025-68889—9.7%
——3——CVE-2025-29426—9.7%
——3——CVE-2026-1805—9.7%
——3——CVE-2023-53694—9.7%
——3——CVE-2026-655645.3 MED9.7%
——3Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.16dCVE-2026-32142—9.7%
——3——CVE-2017-2721—9.7%
——3——CVE-2022-23829—9.7%
——3——CVE-2026-85946.2 MED9.7%
——3Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters.
Text::LineFold splits the input string by specific line break characters (such as VT, FF and others) into segments, but applies the break function to the entire string, not just the segment.
A side effect of this is that the full input can be duplicated for each segment. Besides being incorrect, this can lead to unexpected resource consumption and possible denial of service.
Note that Text::LineFold is part of the Unicode-LineBreak distribution, which may have a higher version number than the module.22dCVE-2025-31450—9.7%
——3——CVE-2026-90226.4 MED9.7%
——3The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload must be published before it executes for site visitors, which requires an editor or administrator to approve and publish the contributor's post.21dCVE-2024-8094—9.7%
——3——CVE-2023-20240—9.7%
——3——CVE-2025-31088—9.7%
——3——CVE-2026-479695.5 MED9.7%
——3Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.29dCVE-2026-562813.8 LOW9.7%
——3Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL queries via template literals. An attacker with platform admin credentials can inject SQL fragments to enumerate dataset schemas, extract analytics data, or cause denial-of-service against the analytics backend.30dCVE-2025-21824—9.7%
——3——CVE-2026-2480—9.7%
——3——CVE-2026-2593—9.7%
——3——CVE-2017-15821—9.7%
——3——CVE-2024-54519—9.7%
——3——CVE-2022-46692—9.7%
——3——CVE-2025-40185—9.7%
——3——CVE-2024-0080—9.7%
——3——CVE-2021-0963—9.7%
——3——CVE-2026-438335.3 MED9.7%
——3Full details and mitigation steps are currently restricted and will be published at a later date.9dCVE-2022-503547.8 HIG9.7%
——3In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix kfd_process_device_init_vm error handling
Should only destroy the ib_mem and let process cleanup worker to free
the outstanding BOs. Reset the pointer in pdd->qpd structure, to avoid
NULL pointer access in process destroy worker.
BUG: kernel NULL pointer dereference, address: 0000000000000010
Call Trace:
amdgpu_amdkfd_gpuvm_unmap_gtt_bo_from_kernel+0x46/0xb0 [amdgpu]
kfd_process_device_destroy_cwsr_dgpu+0x40/0x70 [amdgpu]
kfd_process_destroy_pdds+0x71/0x190 [amdgpu]
kfd_process_wq_release+0x2a2/0x3b0 [amdgpu]
process_one_work+0x2a1/0x600
worker_thread+0x39/0x3d09dCVE-2025-31093—9.7%
——3——CVE-2020-8680—9.7%
——3——