Vulnerabilities exploitable today
352,162in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical2,073
- High6,924
- Medium5,904
- Low547
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-654927.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.5hCVE-2026-654937.5 HIG—
——0Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.5hCVE-2022-42770—0.0%
——0——CVE-2026-6481210.0 CRI—
——0In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session5hCVE-2026-648117.8 HIG—
——0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration5hCVE-2026-648104.3 MED—
——0In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking5hCVE-2026-655167.2 HIG—
——0Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.5hCVE-2026-648098.4 HIG—
——0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter5hCVE-2026-648088.4 HIG—
——0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling5hCVE-2026-648077.8 HIG—
——0In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration5hCVE-2026-648037.8 HIG—
——0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK5hCVE-2026-648027.8 HIG—
——0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration5hCVE-2026-648003.5 LOW—
——0In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default5hCVE-2026-619815.4 MED—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.5hCVE-2026-619734.3 MED—
——0Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.5hCVE-2026-619725.3 MED—
——0Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.5hCVE-2026-619547.5 HIG—
——0Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.5hCVE-2026-654947.1 HIG—
——0Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.5hCVE-2026-654957.5 HIG—
——0Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.5hCVE-2026-619519.8 CRI—
——0Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.5hCVE-2026-619509.3 CRI—
——0Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.5hCVE-2026-655186.5 MED—
——0Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.5hCVE-2026-654964.4 MED—
——0Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.5hCVE-2026-619499.3 CRI—
——0Unauthenticated SQL Injection in Bookly <= 27.7 versions.5hCVE-2026-654977.2 HIG—
——0Administrator PHP Object Injection in Complianz <= 7.5.0 versions.5hCVE-2026-619466.5 MED—
——0Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.5hCVE-2026-654985.3 MED—
——0Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.5hCVE-2026-619456.5 MED—
——0Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data.
This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.5hCVE-2026-619447.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.5hCVE-2026-619437.5 HIG—
——0Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.5hCVE-2026-654996.5 MED—
——0Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.5hCVE-2026-658958.5 HIG—
——0Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.5hCVE-2026-5955510.0 CRI—
——0Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.5hCVE-2026-655007.5 HIG—
——0Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.5hCVE-2026-595547.5 HIG—
——0Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.5hCVE-2026-595477.5 HIG—
——0Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.5hCVE-2026-656088.8 HIG—
——0Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous functions such as exec, system, passthru, or shell_exec. Because FlexDirectory registers this handler for every Flex directory, it bypasses the validation added to Blueprint::dynamicData() in 2.0.7 (GHSA-fj2p-qj2f-74v5). Any authenticated user with create or update permission on any Flex-based directory (Flex Users, Flex Pages, Flex Objects, or custom Flex types) can execute arbitrary shell commands on the server.5hCVE-2026-595458.1 HIG—
——0Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.5hCVE-2026-595418.8 HIG—
——0Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.5hCVE-2026-595136.5 MED—
——0Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.5h