Vulnerabilities exploitable today
358,897in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,704
- High11,656
- Medium7,416
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-40142—9.7%
——3——CVE-2025-31083—9.7%
——3——CVE-2026-76406.4 MED9.7%
——3The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortcode in all versions up to, and including, 8.3.5. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.28dCVE-2025-27899—9.7%
——3——CVE-2026-41418—9.7%
——3——CVE-2026-664385.3 MED9.7%
——3Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.16dCVE-2026-619755.3 MED9.7%
——3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.30dCVE-2025-26742—9.7%
——3——CVE-2025-62174—9.7%
——3——CVE-2025-31088—9.7%
——3——CVE-2023-20240—9.7%
——3——CVE-2026-85946.2 MED9.7%
——3Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters.
Text::LineFold splits the input string by specific line break characters (such as VT, FF and others) into segments, but applies the break function to the entire string, not just the segment.
A side effect of this is that the full input can be duplicated for each segment. Besides being incorrect, this can lead to unexpected resource consumption and possible denial of service.
Note that Text::LineFold is part of the Unicode-LineBreak distribution, which may have a higher version number than the module.22dCVE-2024-8094—9.7%
——3——CVE-2026-90226.4 MED9.7%
——3The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload must be published before it executes for site visitors, which requires an editor or administrator to approve and publish the contributor's post.21dCVE-2025-31450—9.7%
——3——CVE-2022-50557—9.7%
——3——CVE-2025-43789—9.7%
——3——CVE-2025-344674.3 MED9.7%
——3ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege user requests an administrative page, the application returns "404 Not Found" as expected, but incorrectly acquires and associates a temporary lock on the targeted resource with the attacker session prior to authorization. This lock prevents other users, including administrators, from accessing the affected functionality until the attacker navigates away or the session is terminated.29dCVE-2025-40132—9.7%
——3——CVE-2025-22497—9.7%
——3——CVE-2025-31608—9.7%
——3——CVE-2026-24998—9.7%
——3——CVE-2024-53225—9.7%
——3——CVE-2023-53340—9.7%
——3——CVE-2026-31825—9.7%
——3——CVE-2025-31077—9.7%
——3——CVE-2026-142025.3 MED9.7%
——3Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.9dCVE-2026-2343—9.7%
——3——CVE-2025-3165—9.7%
——3——CVE-2026-417305.3 MED9.7%
——3Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients.
Affected versions:
Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.21dCVE-2026-48945—9.7%
——3——CVE-2026-447695.5 MED9.7%
——3SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application.29dCVE-2021-47957—9.7%
——3——CVE-2026-1169—9.7%
——3——CVE-2026-0944—9.7%
——3——CVE-2024-56580—9.7%
——3——CVE-2026-45215—9.7%
——3——CVE-2026-655645.3 MED9.7%
——3Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.16dCVE-2023-32436—9.7%
——3——CVE-2026-666855.3 MED9.7%
——3Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.6h