Vulnerabilities exploitable today
358,897in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,704
- High11,656
- Medium7,416
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-53702—9.7%
——3——CVE-2026-97146.4 MED9.7%
——3The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and including, 1.2 This is due to insufficient input sanitization and output escaping in the showmodule_shortcode() function, which concatenates the 'id' shortcode attribute directly into a dynamically constructed shortcode string without applying esc_attr() or any escaping, allowing an attacker to break out of the attribute context and inject arbitrary HTML. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.23dCVE-2025-43279—9.7%
——3——CVE-2023-20240—9.7%
——3——CVE-2026-90226.4 MED9.7%
——3The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload must be published before it executes for site visitors, which requires an editor or administrator to approve and publish the contributor's post.21dCVE-2025-31450—9.7%
——3——CVE-2024-8094—9.7%
——3——CVE-2026-85946.2 MED9.7%
——3Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters.
Text::LineFold splits the input string by specific line break characters (such as VT, FF and others) into segments, but applies the break function to the entire string, not just the segment.
A side effect of this is that the full input can be duplicated for each segment. Besides being incorrect, this can lead to unexpected resource consumption and possible denial of service.
Note that Text::LineFold is part of the Unicode-LineBreak distribution, which may have a higher version number than the module.22dCVE-2025-31412—9.7%
——3——CVE-2023-20241—9.7%
——3——CVE-2023-53652—9.7%
——3——CVE-2024-8286—9.7%
——3——CVE-2026-1902—9.7%
——3——CVE-2025-31414—9.7%
——3——CVE-2025-31096—9.7%
——3——CVE-2026-619765.3 MED9.7%
——3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.30dCVE-2026-619775.3 MED9.7%
——3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.30dCVE-2025-31604—9.7%
——3——CVE-2025-31434—9.7%
——3——CVE-2026-487475.3 MED9.7%
——3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the request-selected algorithm to hash_hmac(), allowing a signature algorithm downgrade instead of enforcing Mailomat's documented SHA-256 webhook signature. This issue is fixed in versions 7.4.13 and 8.0.13.28dCVE-2024-21826—9.7%
——3——CVE-2026-479695.5 MED9.7%
——3Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.29dCVE-2025-31088—9.7%
——3——CVE-2025-11465—9.7%
——3——CVE-2026-608347.1 HIG9.7%
——3Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with network access via RAD to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Solaris accessible data as well as unauthorized update, insert or delete access to some of Oracle Solaris accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).12dCVE-2023-3091—9.7%
——3——CVE-2021-3740—9.7%
——3——CVE-2025-40153—9.7%
——3——CVE-2026-13426—9.7%
——3——CVE-2025-58234—9.7%
——3——CVE-2025-39546—9.7%
——3——CVE-2024-21151—9.7%
——3——CVE-2025-42598—9.7%
——3——CVE-2025-14804—9.7%
——3——CVE-2025-34264—9.7%
——3——CVE-2026-20637—9.7%
——3——CVE-2023-32660—9.7%
——3——CVE-2023-3379—9.7%
——3——CVE-2025-382538.8 HIG9.7%
——3In the Linux kernel, the following vulnerability has been resolved:
HID: wacom: fix crash in wacom_aes_battery_handler()
Commit fd2a9b29dc9c ("HID: wacom: Remove AES power_supply after extended
inactivity") introduced wacom_aes_battery_handler() which is scheduled
as a delayed work (aes_battery_work).
In wacom_remove(), aes_battery_work is not canceled. Consequently, if
the device is removed while aes_battery_work is still pending, then hard
crashes or "Oops: general protection fault..." are experienced when
wacom_aes_battery_handler() is finally called. E.g., this happens with
built-in USB devices after resume from hibernate when aes_battery_work
was still pending at the time of hibernation.
So, take care to cancel aes_battery_work in wacom_remove().14dCVE-2026-46430—9.7%
——3——