PULSE
LIVE18signals / 24h
FEED
ransomthegentlemen reclama a Philippine Savings Bank · PH · Financial Servicesransomplay reclama a The Butcher Brothers · US · Retail & E-Commerceransomplay reclama a Sigma Plastics Group · US · Manufacturingransomplay reclama a Cambridge Management · US · Professional Servicesransomincransom reclama a quantinuum.com · US · Technologyransomglobal secret group reclama a Vernon & Waldrep · US · Professional Servicesransomqilin reclama a The Saturday Evening Post · US · Otherransomqilin reclama a Commercial Furniture Interiors · US · Retail & E-Commerceransomqilin reclama a Dienst Pack Systems · DE · Manufacturingransomqilin reclama a Ceragres · CA · Manufacturingransomqilin reclama a Pointe Property Group · US · Otherransomqilin reclama a Schreiner Trockenbau GmbH · AT · Manufacturingransomgammax reclama a MTCO (Mahmoud Altaheni & Partners Trading Co) · SA · Otherransomgammax reclama a MTCO (Mahmoud Altaheni & Partners Trading Company) · SA · Professional Servicesransomthegentlemen reclama a Philippine Savings Bank · PH · Financial Servicesransomplay reclama a The Butcher Brothers · US · Retail & E-Commerceransomplay reclama a Sigma Plastics Group · US · Manufacturingransomplay reclama a Cambridge Management · US · Professional Servicesransomincransom reclama a quantinuum.com · US · Technologyransomglobal secret group reclama a Vernon & Waldrep · US · Professional Servicesransomqilin reclama a The Saturday Evening Post · US · Otherransomqilin reclama a Commercial Furniture Interiors · US · Retail & E-Commerceransomqilin reclama a Dienst Pack Systems · DE · Manufacturingransomqilin reclama a Ceragres · CA · Manufacturingransomqilin reclama a Pointe Property Group · US · Otherransomqilin reclama a Schreiner Trockenbau GmbH · AT · Manufacturingransomgammax reclama a MTCO (Mahmoud Altaheni & Partners Trading Co) · SA · Otherransomgammax reclama a MTCO (Mahmoud Altaheni & Partners Trading Company) · SA · Professional Services
CVE Watch354,831 in full archive

Vulnerabilities exploitable today

354,831in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,569
  • High
    9,189
  • Medium
    7,427
  • Low
    692
Filters

Window

Severity

Flags

Vulnerabilities334,121–334,160 · 354,831
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-11128
5.7%
2
CVE-2025-9084
5.7%
2
CVE-2026-22347
5.7%
2
CVE-2026-4420
5.7%
2
CVE-2026-25453
5.7%
2
CVE-2024-49605
5.7%
2
CVE-2021-22463
5.7%
2
CVE-2026-395756.5 MED
5.7%
2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query Blocks: from n/a through <= 5.5.0.8d
CVE-2023-42766
5.7%
2
CVE-2026-8545
5.7%
2
CVE-2026-655186.5 MED
5.7%
2Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.9d
CVE-2025-8774
5.7%
2
CVE-2024-13336
5.7%
2
CVE-2026-655196.5 MED
5.7%
2Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.9d
CVE-2026-396666.5 MED
5.7%
2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in telepathy Hello Bar Popup Builder hellobar allows DOM-Based XSS.This issue affects Hello Bar Popup Builder: from n/a through <= 1.5.1.8d
CVE-2022-1747
5.7%
2
CVE-2026-40038
5.7%
2
CVE-2026-21492
5.7%
2
CVE-2024-49220
5.7%
2
CVE-2026-22568
5.7%
2
CVE-2026-59064.3 MED
5.7%
2Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)9d
CVE-2023-28956
5.7%
2
CVE-2025-32412
5.7%
2
CVE-2026-654656.5 MED
5.7%
2Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.9d
CVE-2026-77755.5 MED
5.7%
2IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.4d
CVE-2023-22429
5.7%
2
CVE-2025-58400
5.7%
2
CVE-2026-25305
5.7%
2
CVE-2024-49237
5.7%
2
CVE-2025-69011
5.7%
2
CVE-2026-394826.5 MED
5.7%
2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post Expirator post-expirator allows DOM-Based XSS.This issue affects Post Expirator: from n/a through <= 4.9.4.8d
CVE-2026-655036.5 MED
5.7%
2Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.9d
CVE-2026-21423
5.7%
2
CVE-2026-32429
5.7%
2
CVE-2026-274036.5 MED
5.7%
2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.9d
CVE-2019-2103
5.7%
2
CVE-2024-49223
5.7%
2
CVE-2026-175704.3 MED
5.7%
2Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier5d
CVE-2026-654496.5 MED
5.7%
2Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.9d
CVE-2026-32403
5.7%
2