Vulnerabilities exploitable today
356,659in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,542
- High10,707
- Medium6,905
- Low691
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-609616.1 MED7.9%
——2Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.34dCVE-2022-26032—7.9%
——2——CVE-2025-40207—7.9%
——2——CVE-2023-28147—7.9%
——2——CVE-2026-118685.3 MED7.9%
——2The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.19dCVE-2026-148435.3 MED7.9%
——2The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record.8dCVE-2020-11257—7.9%
——2——CVE-2020-11258—7.9%
——2——CVE-2023-42973—7.9%
——2——CVE-2026-105706.4 MED7.9%
——2The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to substitute raw ACF field values (retrieved via get_field()) directly into Elementor-rendered HTML without any escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.31dCVE-2026-88826.4 MED7.9%
——2The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.16dCVE-2024-42151—7.9%
——2——CVE-2025-15411—7.9%
——2——CVE-2022-26512—7.9%
——2——CVE-2026-8574—7.9%
——2——CVE-2022-29523—7.9%
——2——CVE-2024-26722—7.9%
——2——CVE-2024-45184—7.9%
——2——CVE-2024-24693—7.9%
——2——CVE-2025-40268—7.9%
——2——CVE-2026-259006.1 MED7.9%
——2Lack of output escaping leads to a XSS vector in the feed modules.19dCVE-2026-30894—7.9%
——2——CVE-2022-26844—7.9%
——2——CVE-2025-22016—7.9%
——2——CVE-2026-40959—7.9%
——2——CVE-2026-48968—7.9%
——2——CVE-2026-64596.4 MED7.9%
——2The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events Calendar. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.31dCVE-2025-12551—7.9%
——2——CVE-2026-60584.5 MED7.9%
——2** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authenticated administrator to visit the “AP Select” page while a malformed SSID is present.32dCVE-2023-28085—7.9%
——2——CVE-2026-1098—7.9%
——2——CVE-2025-21888—7.9%
——2——CVE-2023-53801—7.9%
——2——CVE-2026-73437.5 HIG7.9%
——2Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)15dCVE-2025-40160—7.9%
——2——CVE-2026-133905.3 MED7.9%
——2The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.12dCVE-2024-22029—7.9%
——2——CVE-2020-11282—7.9%
——2——CVE-2020-5928—7.9%
——2——CVE-2022-20581—7.9%
——2——