Vulnerabilities exploitable today
356,780in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,532
- High10,545
- Medium6,712
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-40557—9.2%
——3——CVE-2026-22605—9.2%
——3——CVE-2026-150996.4 MED9.2%
——3The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This is due to insufficient input sanitization and output escaping in the wrap_direction_text() function, which interpolates the user-supplied href value from nested link nodes ($node['props']['href']) directly into an anchor tag via sprintf() at line 1627 without esc_url() or any URL scheme validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts (including javascript: URIs) in pages that will execute whenever a user (such as an editor or administrator previewing the pending post) accesses an injected page and clicks the malicious link.25dCVE-2024-27069—9.2%
——3——CVE-2026-15299—9.2%
——3——CVE-2022-36949—9.2%
——3——CVE-2026-3619—9.2%
——3——CVE-2026-156536.4 MED9.2%
——3The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.17dCVE-2023-52695—9.2%
——3——CVE-2026-342485.7 MED9.2%
——3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could see fields which are not intended for customers - including fields not intended for them at all (e.g. priority, custom ticket attributes for internal purposes). This was the case when a customer opened a ticket from another user of the same shared organization. They are not able to modify these field. This vulnerability is fixed in 7.0.1.17dCVE-2021-47968—9.2%
——3——CVE-2026-8454—9.2%
——3——CVE-2018-5831—9.2%
——3——CVE-2026-4138—9.2%
——3——CVE-2026-3427—9.2%
——3——CVE-2026-153946.4 MED9.2%
——3The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.18dCVE-2026-1236—9.2%
——3——CVE-2024-52976—9.2%
——3——CVE-2026-25028—9.2%
——3——CVE-2023-530397.8 HIG9.2%
——3In the Linux kernel, the following vulnerability has been resolved:
HID: intel-ish-hid: ipc: Fix potential use-after-free in work function
When a reset notify IPC message is received, the ISR schedules a work
function and passes the ISHTP device to it via a global pointer
ishtp_dev. If ish_probe() fails, the devm-managed device resources
including ishtp_dev are freed, but the work is not cancelled, causing a
use-after-free when the work function tries to access ishtp_dev. Use
devm_work_autocancel() instead, so that the work is automatically
cancelled if probe fails.6dCVE-2023-530847.8 HIG9.2%
——3In the Linux kernel, the following vulnerability has been resolved:
drm/shmem-helper: Remove another errant put in error path
drm_gem_shmem_mmap() doesn't own reference in error code path, resulting
in the dma-buf shmem GEM object getting prematurely freed leading to a
later use-after-free.6dCVE-2021-3721—9.2%
——3——CVE-2022-30772—9.2%
——3——CVE-2022-50226—9.2%
——3——CVE-2025-57780—9.2%
——3——CVE-2020-28341—9.2%
——3——CVE-2026-6962—9.2%
——3——CVE-2026-4072—9.2%
——3——CVE-2025-54172—9.2%
——3——CVE-2024-2233—9.2%
——3——CVE-2026-8872—9.2%
——3——CVE-2022-48610—9.2%
——3——CVE-2024-35809—9.2%
——3——CVE-2026-32407—9.2%
——3——CVE-2026-2367—9.2%
——3——CVE-2022-4569—9.2%
——3——CVE-2024-38553—9.2%
——3——CVE-2026-24310—9.2%
——3——CVE-2026-2300—9.2%
——3——CVE-2025-30729—9.2%
——3——