PULSE
LIVE29signals / 24h
FEED
ransomwallstreet reclama a T.RAD North America · US · Technologyransomwallstreet reclama a Black Hills Bentonite · US · Manufacturingransomspacebears reclama a Elixi International SA · CH · Healthcareransomunsafe reclama a DECK APP TECHNOLOGIES PTE. LTD · IN · Technologyransomthegentlemen reclama a CONTAC Ingenieros · CL · Professional Servicesransomthegentlemen reclama a RAK Construction · IN · Manufacturingransomthegentlemen reclama a Lancesoft India · IN · Technologyransomthegentlemen reclama a AIMS Group · GB · Otherransomthegentlemen reclama a AnMed · US · Healthcareransomthegentlemen reclama a NTU Alumni Club · SG · Educationransomthegentlemen reclama a Canopy Support Services · CA · Professional Servicesransomthegentlemen reclama a Mikel Coffee · MX · Retail & E-Commerceransomthegentlemen reclama a Hong Kong Baptist University · HK · Educationransomthegentlemen reclama a Eva Care · GB · Healthcareransomwallstreet reclama a T.RAD North America · US · Technologyransomwallstreet reclama a Black Hills Bentonite · US · Manufacturingransomspacebears reclama a Elixi International SA · CH · Healthcareransomunsafe reclama a DECK APP TECHNOLOGIES PTE. LTD · IN · Technologyransomthegentlemen reclama a CONTAC Ingenieros · CL · Professional Servicesransomthegentlemen reclama a RAK Construction · IN · Manufacturingransomthegentlemen reclama a Lancesoft India · IN · Technologyransomthegentlemen reclama a AIMS Group · GB · Otherransomthegentlemen reclama a AnMed · US · Healthcareransomthegentlemen reclama a NTU Alumni Club · SG · Educationransomthegentlemen reclama a Canopy Support Services · CA · Professional Servicesransomthegentlemen reclama a Mikel Coffee · MX · Retail & E-Commerceransomthegentlemen reclama a Hong Kong Baptist University · HK · Educationransomthegentlemen reclama a Eva Care · GB · Healthcare
CVE Watch356,780 in full archive

Vulnerabilities exploitable today

356,780in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605

Distribution · last window

  • Critical
    2,532
  • High
    10,545
  • Medium
    6,712
  • Low
    670
Filters

Window

Severity

Flags

Vulnerabilities323,681–323,720 · 356,780
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-40557
9.2%
3
CVE-2026-22605
9.2%
3
CVE-2026-150996.4 MED
9.2%
3The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This is due to insufficient input sanitization and output escaping in the wrap_direction_text() function, which interpolates the user-supplied href value from nested link nodes ($node['props']['href']) directly into an anchor tag via sprintf() at line 1627 without esc_url() or any URL scheme validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts (including javascript: URIs) in pages that will execute whenever a user (such as an editor or administrator previewing the pending post) accesses an injected page and clicks the malicious link.25d
CVE-2024-27069
9.2%
3
CVE-2026-15299
9.2%
3
CVE-2022-36949
9.2%
3
CVE-2026-3619
9.2%
3
CVE-2026-156536.4 MED
9.2%
3The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.17d
CVE-2023-52695
9.2%
3
CVE-2026-342485.7 MED
9.2%
3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could see fields which are not intended for customers - including fields not intended for them at all (e.g. priority, custom ticket attributes for internal purposes). This was the case when a customer opened a ticket from another user of the same shared organization. They are not able to modify these field. This vulnerability is fixed in 7.0.1.17d
CVE-2021-47968
9.2%
3
CVE-2026-8454
9.2%
3
CVE-2018-5831
9.2%
3
CVE-2026-4138
9.2%
3
CVE-2026-3427
9.2%
3
CVE-2026-153946.4 MED
9.2%
3The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.18d
CVE-2026-1236
9.2%
3
CVE-2024-52976
9.2%
3
CVE-2026-25028
9.2%
3
CVE-2023-530397.8 HIG
9.2%
3In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: ipc: Fix potential use-after-free in work function When a reset notify IPC message is received, the ISR schedules a work function and passes the ISHTP device to it via a global pointer ishtp_dev. If ish_probe() fails, the devm-managed device resources including ishtp_dev are freed, but the work is not cancelled, causing a use-after-free when the work function tries to access ishtp_dev. Use devm_work_autocancel() instead, so that the work is automatically cancelled if probe fails.6d
CVE-2023-530847.8 HIG
9.2%
3In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Remove another errant put in error path drm_gem_shmem_mmap() doesn't own reference in error code path, resulting in the dma-buf shmem GEM object getting prematurely freed leading to a later use-after-free.6d
CVE-2021-3721
9.2%
3
CVE-2022-30772
9.2%
3
CVE-2022-50226
9.2%
3
CVE-2025-57780
9.2%
3
CVE-2020-28341
9.2%
3
CVE-2026-6962
9.2%
3
CVE-2026-4072
9.2%
3
CVE-2025-54172
9.2%
3
CVE-2024-2233
9.2%
3
CVE-2026-8872
9.2%
3
CVE-2022-48610
9.2%
3
CVE-2024-35809
9.2%
3
CVE-2026-32407
9.2%
3
CVE-2026-2367
9.2%
3
CVE-2022-4569
9.2%
3
CVE-2024-38553
9.2%
3
CVE-2026-24310
9.2%
3
CVE-2026-2300
9.2%
3
CVE-2025-30729
9.2%
3