Vulnerabilities exploitable today
352,162in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical2,073
- High6,924
- Medium5,904
- Low547
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-654947.1 HIG—
——0Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.4hCVE-2026-62165——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61446. Reason: This candidate is a duplicate of CVE-2026-61446. Notes: All CVE users should reference CVE-2026-61446 instead of this candidate.8dCVE-2026-619547.5 HIG—
——0Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.4hCVE-2026-654957.5 HIG—
——0Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.4hCVE-2026-654964.4 MED—
——0Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.4hCVE-2026-619519.8 CRI—
——0Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.4hCVE-2026-654977.2 HIG—
——0Administrator PHP Object Injection in Complianz <= 7.5.0 versions.4hCVE-2026-619509.3 CRI—
——0Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.4hCVE-2026-619499.3 CRI—
——0Unauthenticated SQL Injection in Bookly <= 27.7 versions.4hCVE-2026-654985.3 MED—
——0Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.4hCVE-2026-654996.5 MED—
——0Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.4hCVE-2026-619466.5 MED—
——0Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.4hCVE-2026-655007.5 HIG—
——0Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.4hCVE-2026-619456.5 MED—
——0Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data.
This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.4hCVE-2026-619447.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.4hCVE-2026-157864.9 MED—
——0The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Although file write content is passed through esc_html(), which encodes angle brackets and prevents direct PHP execution, plaintext configuration files such as .htaccess are fully writable and exploitable for denial-of-service or redirect attacks.6hCVE-2026-619437.5 HIG—
——0Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.4hCVE-2026-655055.3 MED—
——0Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.4hCVE-2026-655065.3 MED—
——0Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.4hCVE-2026-655107.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.4hCVE-2026-655117.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.4hCVE-2026-655125.4 MED—
——0Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.4hCVE-2026-655146.5 MED—
——0Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.4hCVE-2026-655167.2 HIG—
——0Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.4hCVE-2026-655186.5 MED—
——0Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.4hCVE-2026-655196.5 MED—
——0Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.4hCVE-2026-655215.3 MED—
——0Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.4hCVE-2026-5955510.0 CRI—
——0Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.4hCVE-2026-595547.5 HIG—
——0Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.4hCVE-2026-655268.5 HIG—
——0Contributor SQL Injection in Visualizer <= 4.0.6 versions.4hCVE-2026-595477.5 HIG—
——0Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.4hCVE-2026-595458.1 HIG—
——0Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.4hCVE-2026-655276.5 MED—
——0Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.4hCVE-2026-595418.8 HIG—
——0Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.4hCVE-2026-655286.5 MED—
——0Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.4hCVE-2026-595136.5 MED—
——0Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.4hCVE-2026-595127.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.4hCVE-2026-655295.3 MED—
——0Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.4hCVE-2026-578097.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.4hCVE-2026-578086.5 MED—
——0Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.4h