Vulnerabilities exploitable today
356,659in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,543
- High10,721
- Medium6,909
- Low694
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-81974.8 MED7.9%
——2Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template renders the integration name (admin-controlled) through Concrete's t() translation helper as a sprintf-style format. The <strong>...</strong> wrap is built by PHP string interpolation before t() runs, so the integration name lands in the translated output as raw HTML. A rogue admin could potentially snoop on login submissions.The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Thanks Yonatan Drori (Tenzai) for reporting.16dCVE-2026-88826.4 MED7.9%
——2The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.16dCVE-2026-88956.4 MED7.9%
——2The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping on the shortcode's 'href' and 'type' attributes, which are concatenated directly into HTML attribute contexts in the shortcode callback registered in kk-blog-card-shortcode.php. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.16dCVE-2020-11258—7.9%
——2——CVE-2026-148435.3 MED7.9%
——2The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the personal data of any person record.8dCVE-2023-42973—7.9%
——2——CVE-2026-118685.3 MED7.9%
——2The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.19dCVE-2025-14445—7.9%
——2——CVE-2025-13959—7.9%
——2——CVE-2023-53801—7.9%
——2——CVE-2022-48842—7.9%
——2——CVE-2026-1098—7.9%
——2——CVE-2026-27677—7.9%
——2——CVE-2026-476977.1 HIG7.9%
——2Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). Prior to version 1.20.2, several endpoints accepted entity IDs from request input and `connect`-ed / read / updated them without verifying the IDs belonged to the caller's organization. An authenticated user in Org A who knew or obtained an ID belonging to Org B could act on Org B's data across organization boundaries (a cross-tenant IDOR). A loader-only restriction on personal-workspace bookings was also bypassable via a crafted POST. Version 1.20.2 patches the issue. No known workarounds are available.16dCVE-2025-59769—7.9%
——2——CVE-2024-13432—7.9%
——2——CVE-2020-9695—7.9%
——2——CVE-2025-12001—7.9%
——2——CVE-2025-30923—7.9%
——2——CVE-2025-46434—7.8%
——2——CVE-2025-57392—7.9%
——2——CVE-2024-48191—7.9%
——2——CVE-2025-23745—7.9%
——2——CVE-2025-59762—7.9%
——2——CVE-2025-10357—7.9%
——2——CVE-2026-26861—7.9%
——2——CVE-2025-59760—7.9%
——2——CVE-2025-59772—7.9%
——2——CVE-2026-21991—7.9%
——2——CVE-2026-43934—7.9%
——2——CVE-2025-59752—7.9%
——2——CVE-2026-600606.3 MED7.9%
——2Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.22dCVE-2024-4429—7.9%
——2——CVE-2026-554325.4 MED7.9%
——2Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum. Exploitation requires the ability to register sub-agent apps in a workspace the attacker controls. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2clamps the sub-agent app sharing level to the template's `MaxPortSharingLevel`. As a workaround, disable wildcard app hostnames (`CODER_WILDCARD_ACCESS_URL`) to block subdomain-based app routing.31dCVE-2023-30693—7.9%
——2——CVE-2025-23743—7.9%
——2——CVE-2026-21907—7.9%
——2——CVE-2026-33092—7.9%
——2——CVE-2026-586287.8 HIG7.9%
——2Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.17dCVE-2024-8270—7.9%
——2——