Vulnerabilities exploitable today
356,659in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,542
- High10,707
- Medium6,905
- Low691
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-45878—7.9%
——2——CVE-2026-24885—7.9%
——2——CVE-2026-6255—7.9%
——2——CVE-2026-44358—7.9%
——2——CVE-2020-5928—7.9%
——2——CVE-2026-133905.3 MED7.9%
——2The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.12dCVE-2022-20581—7.9%
——2——CVE-2020-11282—7.9%
——2——CVE-2024-22029—7.9%
——2——CVE-2026-25293—7.9%
——2——CVE-2026-88856.4 MED7.9%
——2The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on the 'width' and 'align' shortcode attributes within the st_callout() function, which concatenates the attribute values directly into an HTML style attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.17dCVE-2026-585795.4 MED7.9%
——2RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and preserves the node name verbatim. The dataflow-result web UI then renders that name into the "Rerun from current step" confirmation modal via dangerouslySetInnerHTML, and the i18next configuration sets escapeValue:false, so the value is inserted into the DOM without HTML encoding. An authenticated workspace user who can create or edit an agent can inject arbitrary JavaScript that executes in the session of another workspace member who opens the dataflow result and clicks rerun, enabling session/token theft and account takeover across the user trust boundary.25dCVE-2022-20470—7.9%
——2——CVE-2026-27416—7.9%
——2——CVE-2023-53758—7.9%
——2——CVE-2026-100314.2 MED7.9%
——2SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.8dCVE-2025-71122—7.9%
——2——CVE-2025-8681—7.9%
——2——CVE-2025-23278—7.9%
——2——CVE-2026-57665—7.9%
——2——CVE-2024-57913—7.9%
——2——CVE-2026-8803—7.9%
——2——CVE-2026-143225.3 MED7.9%
——2The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.17dCVE-2024-42151—7.9%
——2——CVE-2026-145475.3 MED7.9%
——2The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a mail relay for spam or phishing.2dCVE-2026-57652—7.9%
——2——CVE-2026-472018.5 HIG7.9%
——2authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate as another federated user. This issue has been patched in versions 2025.12.5, 2026.2.3, and 2026.5.1.17dCVE-2022-26421—7.9%
——2——CVE-2024-34332—7.9%
——2——CVE-2020-11259—7.9%
——2——CVE-2025-7835—7.9%
——2——CVE-2022-37329—7.9%
——2——CVE-2025-64378—7.9%
——2——CVE-2025-672906.1 MED7.9%
——2A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field.35dCVE-2026-8896—7.9%
——2——CVE-2026-12276—7.9%
——2——CVE-2019-1993—7.9%
——2——CVE-2024-57878—7.9%
——2——CVE-2026-6662—7.9%
——2——CVE-2025-40311—7.9%
——2——