Vulnerabilities exploitable today
354,831in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,569
- High9,189
- Medium7,427
- Low692
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-11128—5.7%
——2——CVE-2025-9084—5.7%
——2——CVE-2026-22347—5.7%
——2——CVE-2026-4420—5.7%
——2——CVE-2026-25453—5.7%
——2——CVE-2024-49605—5.7%
——2——CVE-2021-22463—5.7%
——2——CVE-2026-395756.5 MED5.7%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query Blocks: from n/a through <= 5.5.0.8dCVE-2023-42766—5.7%
——2——CVE-2026-8545—5.7%
——2——CVE-2026-655186.5 MED5.7%
——2Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.9dCVE-2025-8774—5.7%
——2——CVE-2024-13336—5.7%
——2——CVE-2026-655196.5 MED5.7%
——2Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.9dCVE-2026-396666.5 MED5.7%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in telepathy Hello Bar Popup Builder hellobar allows DOM-Based XSS.This issue affects Hello Bar Popup Builder: from n/a through <= 1.5.1.8dCVE-2022-1747—5.7%
——2——CVE-2026-40038—5.7%
——2——CVE-2026-21492—5.7%
——2——CVE-2024-49220—5.7%
——2——CVE-2026-22568—5.7%
——2——CVE-2026-59064.3 MED5.7%
——2Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)9dCVE-2023-28956—5.7%
——2——CVE-2025-32412—5.7%
——2——CVE-2026-654656.5 MED5.7%
——2Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.9dCVE-2026-77755.5 MED5.7%
——2IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.4dCVE-2023-22429—5.7%
——2——CVE-2025-58400—5.7%
——2——CVE-2026-25305—5.7%
——2——CVE-2024-49237—5.7%
——2——CVE-2025-69011—5.7%
——2——CVE-2026-394826.5 MED5.7%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post Expirator post-expirator allows DOM-Based XSS.This issue affects Post Expirator: from n/a through <= 4.9.4.8dCVE-2026-655036.5 MED5.7%
——2Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.9dCVE-2026-21423—5.7%
——2——CVE-2026-32429—5.7%
——2——CVE-2026-274036.5 MED5.7%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS.
This issue affects Hubbub Lite: from n/a through 1.36.3.9dCVE-2019-2103—5.7%
——2——CVE-2024-49223—5.7%
——2——CVE-2026-175704.3 MED5.7%
——2Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests.
This issue affects :
* Devolutions Server 2026.2.4.0 through 2026.2.12.0
* Devolutions Server 2026.1.23.0 and earlier5dCVE-2026-654496.5 MED5.7%
——2Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.9dCVE-2026-32403—5.7%
——2——